cbcvebase.
CVE-2021-21816
published 2021-07-16

CVE-2021-21816: An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the…

PriorityP340medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EXPLOIT
EPSS
36.49%
98.3th percentile
An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdir-3040_firmware

Detection & IOCsextracted from sources · hover to see the quote

url{{BaseURL}}/messages
snort
57475 - 57478
  • HTTP GET request to /messages endpoint on the target device; response body containing all three strings 'syslog:', 'admin', and '/etc_ro/lighttpd/www' with HTTP 200 status indicates successful exploitation/exposure of the syslog information disclosure vulnerability.
  • The vulnerability is triggered via a specially crafted HTTP GET request to the Syslog functionality endpoint; no authentication required (PR:N) and the response leaks system log contents.
  • ·Snort rules 57475–57478 cover the broader set of D-LINK DIR-3040 vulnerabilities (CVE-2021-21816 through related CVEs); individual rule-to-CVE mapping is not specified in the source.
  • ·Affected version is specifically D-LINK DIR-3040 firmware 1.13B03; Talos confirmed exploitation only against this version.

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.