Vulnerability record · CVE-2021-40655 · published 24 September 2021
CVE-2021-40655: D-Link DIR-605 router credential disclosure via getcfg.php
Dlink · Dir 605l Firmware
D-Link DIR-605 B2 firmware 2.01MT exposes credentials through the /getcfg.php page, which fails to enforce proper authorization. A crafted POST request returns the device username and password, giving attackers administrative access to the router. The flaw is remotely reachable without authentication, making it a serious exposure for internet-facing devices.
Description
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw allows unauthenticated remote credential theft, is listed in CISA KEV, and has a very high EPSS score, with no patch available because the product line is end-of-life.
What it is
D-Link DIR-605 B2 firmware 2.01MT exposes credentials through the /getcfg.php page, which fails to enforce proper authorization. A crafted POST request returns the device username and password, giving attackers administrative access to the router. The flaw is remotely reachable without authentication, making it a serious exposure for internet-facing devices.
Impact
An attacker obtains the router's administrative username and password, enabling full control of the device and any traffic or configuration it manages. This can lead to further network compromise, traffic interception, or use of the router as a pivot point.
Attack surface
Reachable over the network via HTTP through the /getcfg.php endpoint; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the router's web interface can attempt the forged POST request.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2024-05-16, and EPSS gives a 30-day probability of 0.86659 (99.73rd percentile). A public exploit reference exists on GitHub, and no ransomware campaign use is documented.
What to do
- Retire and replace affected D-Link DIR-605 B2 devices, which are end-of-life and end-of-service per CISA's required action.
- If the device cannot be replaced immediately, remove its web interface from internet exposure and restrict management access to a trusted internal network.
- Change default and any exposed administrative credentials, and monitor for unauthorized configuration changes.
- Apply any vendor security bulletin guidance for D-Link legacy products, though no fixed firmware is identified in this record.
Detection
- Monitor router and perimeter logs for POST requests to /getcfg.php, especially from unexpected external sources.
- Alert on outbound or inbound traffic to known D-Link DIR-605 management interfaces from untrusted networks.
- Watch for authentication attempts or configuration changes on the router following suspicious getcfg.php access.
- Use network scanning to identify internet-exposed D-Link DIR-605 devices and prioritize their removal.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-40655 to the Known Exploited Vulnerabilities catalog on 16 May 2024 as "D-Link DIR-605 Router Information Disclosure Vulnerability". Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Federal deadline 6 June 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Ilovewomen/D-LINK-DIR-605/ | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
| https://github.com/Ilovewomen/D-LINK-DIR-605/ | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40655 | US Government Resource |
Track CVE-2021-40655 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40655), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.