Skip to content
COOEY

EXPOSURES › CVE-2021-40655

CVE-2021-40655

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-40655 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedsupply-chaindata-breach

D-Link DIR-605 routers allow attackers to extract admin credentials via forged POST requests to /getcfg.php.

This information disclosure flaw enables attackers to harvest administrator usernames and passwords, directly undermining CMMC and FedRAMP vendor security controls. D-Link's history of unpatched RCEs and command injection in similar firmware makes this a high-risk supply chain failure for defense contractors. Organizations must immediately audit deployed DIR-605 devices and replace them with patched hardware to avoid credential theft and potential lateral movement.

Shame score — Active exploitation of a vendor with a documented history of critical firmware vulnerabilities indicates a systemic failure in patch management and security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.