CVE-2021-20134 describes an absolute path traversal vulnerability in Quagga Services on D-Link DIR-2640 routers running firmware version 1.11B02 or earlier. A remote, authenticated attacker can exploit this flaw to set an arbitrary file as a log file, enabling the appending of data to it. This vulnerability carries a CVSS score of 8.4 (High), indicating a high-impact attack that can lead to remote code execution and an unauthenticated root shell on the device. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11b02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-2640-us_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Critical Vulnerabilities on the D-Link DIR-2640 Router
Oct 19, 2021Critical Vulnerabilities on the D-Link DIR-2640 Router
Oct 19, 2021Critical Vulnerabilities on the D-Link DIR-2640 Router
Oct 19, 2021Critical Vulnerabilities on the D-Link DIR-2640 Router
Oct 19, 2021Critical Vulnerabilities on the D-Link DIR-2640 Router
Oct 19, 2021