Lucene search

K
cvelistTalosCVELIST:CVE-2021-21820
HistoryJul 16, 2021 - 10:24 a.m.

CVE-2021-21820

2021-07-1610:24:07
CWE-798
talos
www.cve.org
6
hard-coded password
vulnerability
d-link dir-3040

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.006

Percentile

78.7%

A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CNA Affected

[
  {
    "product": "D-Link",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "D-LINK DIR-3040 1.13B03"
      }
    ]
  }
]

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.006

Percentile

78.7%

Related for CVELIST:CVE-2021-21820