CVE-2021-21819 β€” OS Command Injection in Dlink Dir-3040 Firmware

Severity
7.2HIGHNVD
EPSS
1.3%
top 20.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 16
Latest updateMay 24

Description

A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

β–ΆNVDdlink/dir-3040_firmware1.13b03

πŸ”΄Vulnerability Details

2
GHSA
GHSA-chxw-2vjc-ppm6: A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1β†—2022-05-24
β–Ά
CVEList
CVE-2021-21819: A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1β†—2021-07-16
β–Ά
CVE-2021-21819 β€” OS Command Injection in Dlink | cvebase