Information Disclosure in D-LINK DIR-3040 WiFi Smart Mesh Functionality
CVE-2021-21913

10CRITICAL

Key Information:

Vendor
D-Link
Status
Vendor
CVE Published:
23 September 2021

Summary

An information disclosure vulnerability is present in the WiFi Smart Mesh functionality of D-LINK DIR-3040 version 1.13B03. By crafting a specific network request, an attacker can exploit this weakness to achieve unauthorized command execution. This vulnerability allows malicious actors to connect to the MQTT service, potentially compromising the device and the network's integrity.

Affected Version(s)

D-Link D-LINK DIR-3040 1.13B03

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.