Path Traversal Vulnerability in D-Link DIR-2640 Quagga Services
CVE-2021-20133
6.1MEDIUM
What is CVE-2021-20133?
The D-Link DIR-2640 router is susceptible to an absolute path traversal vulnerability affecting its Quagga services. This flaw enables a remote, authenticated attacker to manipulate the 'message of the day' banner, potentially disclosing sensitive system files to unauthorized users. Through this vulnerability, attackers can access hashed credentials, plaintext passwords, configuration files, and private keys, which significantly increases the risk of data breaches. Additionally, improper filename handling may lead to denial of service attacks against the Quagga services' command line interfaces, impacting network stability and security.
Affected Version(s)
Quagga Services on D-Link DIR-2640 Routers <= 1.11B02