D Link · D-Link Dir-615 T1 · CVE-2021-40654
**Name of the Vulnerable Software and Affected Versions**
D-LINK-DIR-615 B2 version 2.01mt
D-Link DIR-615 Q1 (affected versions not specified)
**Description**
An information disclosure issue exists, allowing an attacker to obtain a user name and password by forging a post request to the "/getcfg.php" page. This is due to insufficient protection of registration data, which can be exploited by a remote attacker to gain unauthorized access to protected information.
**Recommendations**
For D-LINK-DIR-615 B2 version 2.01mt: As a temporary workaround, consider restricting access to the "/getcfg.php" page until a patch is available.
For D-Link DIR-615 Q1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.