← Vulnerability feed

Vulnerability record · CVE-2021-40655 · published 24 September 2021

CVE-2021-40655: D-Link DIR-605 router credential disclosure via getcfg.php

Dlink · Dir 605l Firmware

D-Link DIR-605 B2 firmware 2.01MT exposes credentials through the /getcfg.php page, which fails to enforce proper authorization. A crafted POST request returns the device username and password, giving attackers administrative access to the router. The flaw is remotely reachable without authentication, making it a serious exposure for internet-facing devices.

7.5 CVSS 3.1 High CISA KEV since 16 May 2024 EPSS 87% · top 0.3% CWE-863 · Incorrect authorization
7.5CVSS 3.1 base score, v2 5.0
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows unauthenticated remote credential theft, is listed in CISA KEV, and has a very high EPSS score, with no patch available because the product line is end-of-life.

What it is

D-Link DIR-605 B2 firmware 2.01MT exposes credentials through the /getcfg.php page, which fails to enforce proper authorization. A crafted POST request returns the device username and password, giving attackers administrative access to the router. The flaw is remotely reachable without authentication, making it a serious exposure for internet-facing devices.

Impact

An attacker obtains the router's administrative username and password, enabling full control of the device and any traffic or configuration it manages. This can lead to further network compromise, traffic interception, or use of the router as a pivot point.

Attack surface

Reachable over the network via HTTP through the /getcfg.php endpoint; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the router's web interface can attempt the forged POST request.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2024-05-16, and EPSS gives a 30-day probability of 0.86659 (99.73rd percentile). A public exploit reference exists on GitHub, and no ransomware campaign use is documented.

What to do

  • Retire and replace affected D-Link DIR-605 B2 devices, which are end-of-life and end-of-service per CISA's required action.
  • If the device cannot be replaced immediately, remove its web interface from internet exposure and restrict management access to a trusted internal network.
  • Change default and any exposed administrative credentials, and monitor for unauthorized configuration changes.
  • Apply any vendor security bulletin guidance for D-Link legacy products, though no fixed firmware is identified in this record.

Detection

  • Monitor router and perimeter logs for POST requests to /getcfg.php, especially from unexpected external sources.
  • Alert on outbound or inbound traffic to known D-Link DIR-605 management interfaces from untrusted networks.
  • Watch for authentication attempts or configuration changes on the router following suspicious getcfg.php access.
  • Use network scanning to identify internet-exposed D-Link DIR-605 devices and prioritize their removal.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-40655 to the Known Exploited Vulnerabilities catalog on 16 May 2024 as "D-Link DIR-605 Router Information Disclosure Vulnerability". Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Federal deadline 6 June 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40655 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-8361Realtek SDK miniigd SOAP service remote code executionThe miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw…KEVEPSS 100%analysed9.8CVE-2023-29961Dlink dir-605l firmware out-of-bounds write vulnerabilityD-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,EPSS 1.2%9.8CVE-2023-24348Dlink dir-605l firmware out-of-bounds write vulnerabilityD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.EPSS 1.2%9.8CVE-2023-24349Dlink dir-605l firmware out-of-bounds write vulnerabilityD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.EPSS 1.2%9.8CVE-2023-24350Dlink dir-605l firmware out-of-bounds write vulnerabilityD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetE…EPSS 1.2%9.8CVE-2023-24351Dlink dir-605l firmware out-of-bounds write vulnerabilityD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.EPSS 1.2%9.8CVE-2023-24352Dlink dir-605l firmware out-of-bounds write vulnerabilityD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.EPSS 1.2%9.3CVE-2012-10021Dlink dir-605l firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode(…EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2021-40655), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.