← All CVEs

CVE-2021-42627

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

9.8
CVSS
63.1%
EPSS (exploit prob.)
99th
EPSS percentile
2022-08-23
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
dlinkdir-615_firmware20.06
dlinkdir-615all versions
dlinkdir-615_j1_firmware20.06
dlinkdir-615_j1all versions
dlinkdir-615_t1_firmware20.06
dlinkdir-615_t1all versions
dlinkdir-615jx10_firmware20.06
dlinkdir-615jx10all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-42627