← Vulnerability feed

Vulnerability record · CVE-2021-3708 · published 16 August 2021

CVE-2021-3708: Dlink dsl-2750u firmware os command injection vulnerability

Dlink · Dsl 2750u Firmware

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.

7.8 CVSS 3.1 High EPSS 25% · top 2.2% CWE-78 · OS command injection
7.8CVSS 3.1 base score, v2 7.2
25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-3708 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-1010155Dlink dsl-2750u firmware vulnerabilityD-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE:…EPSS 8.6%7.8CVE-2020-13150Dlink dsl-2750u firmware missing authentication for critical function vulnerabilityD-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filterin…EPSS 0.28%6.8CVE-2023-46033Dlink dsl-2730u firmware improper access control vulnerabilityD-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the…EPSS 0.33%5.5CVE-2021-3707Dlink dsl-2750u firmware vulnerabilityD-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker…EPSS 1.5%5.3CVE-2024-0717Dlink dir-825acg1 firmware information exposure vulnerabilityA vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DI…EPSS 18%5.1CVE-2024-9792Dlink dsl-2750u firmware cross-site scripting vulnerabilityA vulnerability classified as problematic has been found in D-Link DSL-2750U R5B017. This affects an unknown part of the component Port Forwarding Pa…EPSS 0.68%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed

Source: NIST National Vulnerability Database (record CVE-2021-3708), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.