cbcvebase.
CVE-2021-42627
published 2022-08-23

CVE-2021-42627: The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose…

PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
63.07%
99.1th percentile
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

Affected

4 ranges
VendorProductVersion rangeFixed in
dlinkdir-615_firmware
dlinkdir-615_j1_firmware
dlinkdir-615_t1_firmware
dlinkdir-615jx10_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/wan.htm
  • Unauthenticated GET request to /wan.htm returns HTTP 200 with body containing both "src='menu.js?v=\"+Math.random()+\"'>');" and "var ipv6conntype", and response header containing "Virtual Web" — confirms vulnerable D-Link DIR-615 firmware 20.06 exposure.
  • Shodan queries "http.title:\"Roteador Wireless\"" and cpe:"cpe:2.3:h:dlink:dir-615" can be used to identify internet-exposed D-Link DIR-615 devices potentially affected by this vulnerability.
  • ·Vulnerability is specific to D-Link DIR-615 devices running firmware version 20.06 only.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.