CVE-2021-42627
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
9.8
CVSS
63.1%
EPSS (exploit prob.)
99th
EPSS percentile
2022-08-23
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| dlink | dir-615_firmware | 20.06 |
| dlink | dir-615 | all versions |
| dlink | dir-615_j1_firmware | 20.06 |
| dlink | dir-615_j1 | all versions |
| dlink | dir-615_t1_firmware | 20.06 |
| dlink | dir-615_t1 | all versions |
| dlink | dir-615jx10_firmware | 20.06 |
| dlink | dir-615jx10 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-42627