Path Traversal Vulnerability in D-Link DIR-2640 Quagga Services
CVE-2021-20133
6.1MEDIUM
Summary
The D-Link DIR-2640 router is susceptible to an absolute path traversal vulnerability affecting its Quagga services. This flaw enables a remote, authenticated attacker to manipulate the 'message of the day' banner, potentially disclosing sensitive system files to unauthorized users. Through this vulnerability, attackers can access hashed credentials, plaintext passwords, configuration files, and private keys, which significantly increases the risk of data breaches. Additionally, improper filename handling may lead to denial of service attacks against the Quagga services' command line interfaces, impacting network stability and security.
Affected Version(s)
Quagga Services on D-Link DIR-2640 Routers <= 1.11B02
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved