9.8

CVE-2021-42627

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DlinkDir-615 Firmware Version20.06
   DlinkDir-615 Version-
DlinkDir-615 J1 Firmware Version20.06
   DlinkDir-615 J1 Version-
DlinkDir-615 T1 Firmware Version20.06
   DlinkDir-615 T1 Version-
DlinkDir-615jx10 Firmware Version20.06
   DlinkDir-615jx10 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 49.71% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H