← Vulnerability feed

Vulnerability record · CVE-2021-21816 · published 16 July 2021

CVE-2021-21816: Dlink dir-3040 firmware information exposure vulnerability

Dlink · Dir 3040 Firmware

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

4.3 CVSS 3.1 Medium EPSS 32% · top 1.7% CWE-200 · Information exposure
4.3CVSS 3.1 base score, v2 4.3
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21816 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44832Dlink dir-3040 firmware command injection vulnerabilityD-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.EPSS 4.0%9.8CVE-2021-21913Dlink dir-3040 firmware hard-coded credentials vulnerabilityAn information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request c…EPSS 2.2%9.8CVE-2021-21820Dlink dir-3040 firmware hard-coded credentials vulnerabilityA hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network reque…EPSS 3.0%8.8CVE-2023-41229Dlink dir-3040 firmware heap-based buffer overflow vulnerabilityD-Link DIR-3040 HTTP Request Processing Referer Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adj…EPSS 1.0%8.8CVE-2023-41230Dlink dir-3040 firmware stack-based buffer overflow vulnerabilityD-Link DIR-3040 HTTP Request Processing Referer Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-ad…EPSS 0.96%8.8CVE-2022-43648Dlink dir-3040 firmware heap-based buffer overflow vulnerabilityThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 1.20B03 routers. Authenti…EPSS 0.91%7.8CVE-2022-1262Dlink dir-1360 firmware os command injection vulnerabilityA command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary comm…EPSS 2.2%7.5CVE-2021-21817Dlink dir-3040 firmware information exposure vulnerabilityAn information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network …EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2021-21816), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.