CVE-2021-3708

Severity
7.8HIGH
EPSS
17.1%
top 5.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16
Latest updateMay 24

Description

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

â–¶CVEListV5d-link/dsl-2750ufirmware vME1.16 or prior versions

🔴Vulnerability Details

3
GHSA
GHSA-37xh-hrqc-3q2v: D-Link router DSL-2750U with firmware vME1↗2022-05-24
â–¶
CVEList
CVE-2021-3708: D-Link router DSL-2750U with firmware vME1↗2021-08-16
â–¶
VulnCheck
D-Link dsl-2750u_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')↗2021
â–¶
CVE-2021-3708 (HIGH CVSS 7.8) | D-Link router DSL-2750U with firmwa | cvebase.io