CyberSec.Space Logo
Back to CVE Browser

CVE-2021-20132

HIGH
8.8
CVSS Severity Score
EPSS Score0.0500%
EPSS Percentile44.13th
PublishedDec 30, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the "admin" user, UID 0).

Affected Platforms (CPE)

💻
Dlink

Dir 2640 Us Firmware

<= 1.11b02

References & Advisories

Related Vulnerabilities