CVE-2021-3707
published 2021-08-16CVE-2021-3707: D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the…
PriorityP430medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
1.54%
72.0th percentile
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dsl-2750u | — | — |
| dlink | dsl-2750u_firmware | <= 1.16 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vulncheck5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-37xh-hrqc-3q2v: D-Link router DSL-2750U with firmware vME1
ghsa_unreviewed·2022-05-24·CVSS 5.5
CVE-2021-3708 [MEDIUM] CWE-78 GHSA-37xh-hrqc-3q2v: D-Link router DSL-2750U with firmware vME1
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.
GHSA
GHSA-q2w4-9m66-g5ff: D-Link router DSL-2750U with firmware vME1
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-3707 [HIGH] CWE-862 GHSA-q2w4-9m66-g5ff: D-Link router DSL-2750U with firmware vME1
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.
VulnCheck
D-Link dsl-2750u_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2021·CVSS 5.5
CVE-2021-3708 [MEDIUM] D-Link dsl-2750u_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
D-Link dsl-2750u_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.
Affected: D-Link dsl-2750u_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-19&host_type=src&vulnerability=cve-2021-3708; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/HadiMed/firmware-analysis/blob/main/DSL-2750U%20%28firmware%20version%201.6%29/README.mdhttps://jvn.jp/en/vu/JVNVU92088210/https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10230https://github.com/HadiMed/firmware-analysis/blob/main/DSL-2750U%20%28firmware%20version%201.6%29/README.mdhttps://jvn.jp/en/vu/JVNVU92088210/https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10230
2021-08-16
Published