← Vulnerability feed

Vulnerability record · CVE-2021-42627 · published 23 August 2022

CVE-2021-42627: D-Link DIR-615 WAN page exposed without authentication

Dlink · Dir 615 Firmware

The WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated remote user can read WAN settings and modify fields on the page, giving full control over WAN configuration.

9.8 CVSS 3.1 Critical EPSS 63% · top 0.8%
9.8CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
9 Jul 2026Last modified by NVD

Description

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required and high EPSS, allowing full read/write control of WAN settings on internet-exposed routers.

What it is

The WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated remote user can read WAN settings and modify fields on the page, giving full control over WAN configuration.

Impact

An attacker gains read and write access to WAN settings, enabling disclosure of network configuration and tampering with the device's WAN parameters, which can disrupt or redirect connectivity.

Attack surface

Reachable over the network via HTTP to the wan.htm page; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and description confirm no authentication or user interaction is required.

Exploitation

Not listed in CISA KEV and no ransomware usage documented; EPSS is high at 0.6307 (99.165th percentile), and references are only third-party and vendor advisories with no public exploit tag.

What to do

  • Apply the latest D-Link firmware for DIR-615 (20.06 is the affected version cited) or replace end-of-support units.
  • Restrict administrative and WAN page access to trusted management networks; do not expose the router web interface to the internet.
  • Disable remote management/WAN-side web access where the feature exists.
  • Monitor D-Link security bulletins for updated guidance on affected DIR-615 revisions.

Detection

  • Review router and perimeter logs for unauthenticated HTTP requests to /wan.htm or similar WAN configuration paths.
  • Alert on configuration changes to WAN settings made outside approved maintenance windows.
  • Baseline WAN configuration values and detect unexpected modifications.
  • Watch for scanning activity targeting D-Link router web interfaces from external sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42627 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2014-8361Realtek SDK miniigd SOAP service remote code executionThe miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw…KEVEPSS 100%analysed10.0CVE-2018-25115Dlink dir-110 firmware os command injection vulnerabilityMultiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…EPSS 10%9.8CVE-2021-37388Dlink dir-615 firmware classic buffer overflow vulnerabilityA buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver …EPSS 3.7%9.8CVE-2019-18852Dlink dir-600 b1 firmware cleartext transmission vulnerabilityCertain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_si…EPSS 1.6%9.8CVE-2018-15839D-Link DIR-615 router buffer overflow via long Authorization headerD-Link DIR-615 firmware contains a memory buffer overflow (CWE-119) triggered by an overly long Authorization HTTP header. The flaw is remotely reach…EPSS 45%analysed8.8CVE-2019-17525Dlink dir-615 firmware improper restriction of authentication attempts vulnerabilityThe login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.EPSS 5.8%8.8CVE-2020-9534Dlink dir-615jx10 firmware out-of-bounds write vulnerabilityfmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is malformed.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-42627), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.