← Vulnerability feed

Vulnerability record · CVE-2021-3707 · published 16 August 2021

CVE-2021-3707: Dlink dsl-2750u firmware vulnerability

Dlink · Dsl 2750u Firmware

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.

5.5 CVSS 3.1 Medium EPSS 1.5% · top 26.1% CWE-15 · CWE-15
5.5CVSS 3.1 base score, v2 2.1
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-3707 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-1010155Dlink dsl-2750u firmware vulnerabilityD-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE:…EPSS 8.6%7.8CVE-2021-3708Dlink dsl-2750u firmware os command injection vulnerabilityD-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local netwo…EPSS 25%7.8CVE-2020-13150Dlink dsl-2750u firmware missing authentication for critical function vulnerabilityD-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filterin…EPSS 0.28%6.8CVE-2023-46033Dlink dsl-2730u firmware improper access control vulnerabilityD-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the…EPSS 0.33%5.3CVE-2024-0717Dlink dir-825acg1 firmware information exposure vulnerabilityA vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DI…EPSS 18%5.1CVE-2024-9792Dlink dsl-2750u firmware cross-site scripting vulnerabilityA vulnerability classified as problematic has been found in D-Link DSL-2750U R5B017. This affects an unknown part of the component Port Forwarding Pa…EPSS 0.68%8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed10.0CVE-2025-47812Wing FTP Server null byte handling leads to Lua code injection RCEWing FTP Server before 7.4.4 mishandles '\0' bytes in its user and admin web interfaces, allowing injection of arbitrary Lua code into user session f…KEVEPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2021-3707), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.