Vulnerability record · CVE-2021-42627 · published 23 August 2022
CVE-2021-42627: D-Link DIR-615 WAN page exposed without authentication
Dlink · Dir 615 Firmware
The WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated remote user can read WAN settings and modify fields on the page, giving full control over WAN configuration.
Description
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and high EPSS, allowing full read/write control of WAN settings on internet-exposed routers.
What it is
The WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated remote user can read WAN settings and modify fields on the page, giving full control over WAN configuration.
Impact
An attacker gains read and write access to WAN settings, enabling disclosure of network configuration and tampering with the device's WAN parameters, which can disrupt or redirect connectivity.
Attack surface
Reachable over the network via HTTP to the wan.htm page; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and description confirm no authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS is high at 0.6307 (99.165th percentile), and references are only third-party and vendor advisories with no public exploit tag.
What to do
- Apply the latest D-Link firmware for DIR-615 (20.06 is the affected version cited) or replace end-of-support units.
- Restrict administrative and WAN page access to trusted management networks; do not expose the router web interface to the internet.
- Disable remote management/WAN-side web access where the feature exists.
- Monitor D-Link security bulletins for updated guidance on affected DIR-615 revisions.
Detection
- Review router and perimeter logs for unauthenticated HTTP requests to /wan.htm or similar WAN configuration paths.
- Alert on configuration changes to WAN settings made outside approved maintenance windows.
- Baseline WAN configuration values and detect unexpected modifications.
- Watch for scanning activity targeting D-Link router web interfaces from external sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/sanjokkarki/D-Link-DIR-615/blob/main/CVE-2021-42627 | Third Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
| https://github.com/sanjokkarki/D-Link-DIR-615/blob/main/CVE-2021-42627 | Third Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
Track CVE-2021-42627 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-42627), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.