PT-2021-5244 · D Link · D-Link Dir-2640-Us+1
Liyansong2018
·
Published
2021-02-08
·
Updated
2024-02-14
·
CVE-2021-34204
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-2640-US version 1.01B04
Description
The issue is related to insufficiently protected credentials. The D-Link AC2600 (DIR-2640) stores the device system account password in plain text and does not utilize Linux user management. Furthermore, all devices have the same password, which cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.
Recommendations
For D-Link DIR-2640-US version 1.01B04, consider disabling access to the serial port as a temporary workaround to minimize the risk of exploitation. Restricting root privileges until a proper fix is available is also advisable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Ac2600
D-Link Dir-2640-Us