CVE-2021-21820 is a critical hard-coded password vulnerability in the Libcli Test Environment of D-Link DIR-3040 1.13B03 routers, allowing unauthenticated attackers to achieve remote code execution through specially crafted network requests. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 11 mentions and media coverage, indicating awareness and potential future exploitation. D-Link has released a hotfix to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.13b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-3040_firmware:1.13b03:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.