CRITICAL🇵🇱 Wersja polska

CVE-2021-42627

CVSS 9.8v3.1pub. 2022-08-23upd. 2026-07-09

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 615

    HW
    Dlink
    all versions
  • Dlink Dir 615 Firmware

    OS
    Dlink
    20.06
  • Dlink Dir 615 J1

    HW
    Dlink
    all versions
  • Dlink Dir 615 J1 Firmware

    OS
    Dlink
    20.06
  • Dlink Dir 615jx10

    HW
    Dlink
    all versions
  • Dlink Dir 615jx10 Firmware

    OS
    Dlink
    20.06
  • Dlink Dir 615 T1

    HW
    Dlink
    all versions
  • Dlink Dir 615 T1 Firmware

    OS
    Dlink
    20.06
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-16920CRITICAL9.8⚠ KEVPL ✓same product

D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI

CVE-2014-8361CRITICAL9.8⚠ KEVPL ✓same product

RCE w usłudze miniigd SOAP Realtek SDK — D-Link DIR-605L/905L

CVE-2018-25115CRITICAL10.0PL ✓same product

D-Link DIR-series — nieuwierzytelniony command injection w service.cgi (root RCE)

CVE-2021-37388CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DIR-615 — możliwy RCE przez ping_ipaddr

CVE-2019-18852CRITICAL9.8PL ✓same product

D-Link — hardcodowane konto Alphanetworks z dostępem TELNET