ZeroHour

CVE-2021-40655

KEV PoC large

Unauthenticated credential disclosure in D-Link DIR-605 router (getcfg.php)

CISA: D-Link DIR-605 Router Information Disclosure Vulnerability

CVSS 3.1
7.5 high
EPSS
87%p100
Published
()
KEV added
AI analysis

CVE-2021-40655 is an unauthenticated information-disclosure flaw (CWE-863, incorrect authorization) in D-Link DIR-605 routers running B2 hardware revision firmware version 2.01MT. An attacker can trigger it remotely by forging a crafted POST request to the device's /getcfg.php page, with no credentials or user interaction required. The flaw returns the router's user name and password, giving the attacker valid credentials for the device's management interface and exposing confidential configuration data; the CVSS 7.5 score reflects high confidentiality impact with no direct integrity or availability impact. Only the legacy DIR-605 is affected, and per CISA all associated hardware revisions have reached end-of-life/end-of-service, so no fixed firmware should be expected from the vendor. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-05-16 amid headlines warning of actively exploited D-Link router flaws, a public proof-of-concept exists on GitHub, and EPSS assigns an 86.7% probability of exploitation within 30 days (percentile 100); ransomware use is unknown.

What to do: Because the DIR-605 is end-of-life/end-of-service with no fixed firmware available, CISA's required action is to retire and replace affected units per vendor instructions. As interim mitigation, restrict or disable WAN-side (internet-facing) management so /getcfg.php is unreachable from the internet, and rotate any exposed administrative credentials. Defenders with internet-facing D-Link routers should inventory against this KEV entry and prioritize replacement of remaining DIR-605 units.

Affected
D-Link DIR-605 router, B2 hardware revision (CPE entry: dir-605l firmware)Firmware 2.01MT
Estimated exposure
largetens of thousands of internet-exposed legacy units (estimated; the historical deployed base is likely far larger) — No install or scan counts are provided in the data; the estimate reflects the DIR-605's mass-market consumer distribution in the early 2010s and public internet scans that repeatedly show legacy D-Link DIR-series routers among exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

CISA Known Exploited Vulnerability
Affected
D-Link DIR-605 Router
Required action
This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-605l firmware
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news