US Government Warns of D-Link Router Security Flaws: Patch Now or Potentially Pay the Price

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities, found in some D-Link routers, to its Known Exploited Vulnerabilities (KEV) database, meaning it has evidence of abuse In nature.

The two vulnerabilities are tracked as CVE-20214-100005 and CVE-2021-40655. The first is a Cross-Site Request Forgery (CSRF) flaw, found on D-Link DIR-600 routers, while the second is an information disclosure flaw found on D-Link DIR-600 routers. 605. The former allows threat actors to change router configurations, while the latter allows the theft of login credentials.

scroll to top