Description
D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.
Published: 2021-06-16
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-20866 D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.
History

No history.

Subscriptions

Dlink Dir-2640-us Dir-2640-us Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T00:05:52.356Z

Reserved: 2021-06-07T00:00:00.000Z

Link: CVE-2021-34204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-16T20:15:07.647

Modified: 2024-11-21T06:10:00.930

Link: CVE-2021-34204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses