Path Traversal Vulnerability in D-Link DIR-2640 Quagga Services
CVE-2021-20133

6.1MEDIUM

Key Information:

Vendor
D-Link
Vendor
CVE Published:
30 December 2021

Summary

The D-Link DIR-2640 router is susceptible to an absolute path traversal vulnerability affecting its Quagga services. This flaw enables a remote, authenticated attacker to manipulate the 'message of the day' banner, potentially disclosing sensitive system files to unauthorized users. Through this vulnerability, attackers can access hashed credentials, plaintext passwords, configuration files, and private keys, which significantly increases the risk of data breaches. Additionally, improper filename handling may lead to denial of service attacks against the Quagga services' command line interfaces, impacting network stability and security.

Affected Version(s)

Quagga Services on D-Link DIR-2640 Routers <= 1.11B02

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.