CVE-2021-33267 is a critical stack buffer overflow vulnerability affecting D-Link DIR-809 devices running firmware through DIR-809Ax_FW1.12WWB03_20190410. This flaw, residing in the /formStaticDHCP function, can be triggered by an unauthenticated attacker sending a specially crafted POST request. With a CVSS score of 9.8 (CRITICAL), successful exploitation allows for complete compromise of confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently known and it's not on CISA's KEV catalog, its high FAUCET Risk Score of 81/100 indicates significant potential danger. There is no evidence of active exploitation or community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.12wwb03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-809_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.