PT-2021-5244 · D Link · D-Link Dir-2640-Us+1

Liyansong2018

·

Published

2021-02-08

·

Updated

2024-02-14

·

CVE-2021-34204

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-2640-US version 1.01B04
Description The issue is related to insufficiently protected credentials. The D-Link AC2600 (DIR-2640) stores the device system account password in plain text and does not utilize Linux user management. Furthermore, all devices have the same password, which cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.
Recommendations For D-Link DIR-2640-US version 1.01B04, consider disabling access to the serial port as a temporary workaround to minimize the risk of exploitation. Restricting root privileges until a proper fix is available is also advisable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2021-06048
CVE-2021-34204

Affected Products

D-Link Ac2600
D-Link Dir-2640-Us