EXPOSURES › CVE-2021-40655
CVE-2021-40655
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link DIR-605 routers allow attackers to extract admin credentials via forged POST requests to /getcfg.php.
This information disclosure flaw enables attackers to harvest administrator usernames and passwords, directly undermining CMMC and FedRAMP vendor security controls. D-Link's history of unpatched RCEs and command injection in similar firmware makes this a high-risk supply chain failure for defense contractors. Organizations must immediately audit deployed DIR-605 devices and replace them with patched hardware to avoid credential theft and potential lateral movement.
Shame score — Active exploitation of a vendor with a documented history of critical firmware vulnerabilities indicates a systemic failure in patch management and security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.