CVE-2021-21816 is an information disclosure vulnerability in the Syslog functionality of D-Link DIR-3040 1.13B03 routers. An attacker can trigger this vulnerability by sending a specially crafted HTTP request, leading to the disclosure of sensitive information. With a CVSS score of 4.3 (Medium), the attack requires no privileges and has low complexity, but relies on user interaction (UI:R) for successful exploitation. While not listed on the KEV catalog, its high EPSS and FAUCET Risk Scores, along with the availability of Nuclei templates, indicate a significant potential for exploitation. Community discussion and media coverage further highlight the attention this vulnerability has received.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.13b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-3040_firmware:1.13b03:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.