CVE Feed

    Dashboard / CVE / CVE-2021-20134

    CVE-2021-20134

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file on the router's filesystem as the log file used by either Quagga service (zebra or ripd). Subsequent log messages will be appended to the file, prefixed by a timestamp and some logging metadata. Remote code execution can be achieved by using this vulnerability to append to a shell script on the router's filesystem, and then awaiting or triggering the execution of that script. A remote, unauthenticated root shell can easily be obtained on the device in this fashion.

    Published:Dec 30, 2021
    Last Modified:Nov 21, 2024
    EPS:Dec 30, 2021
    EPSS Score:0.01093
    CVSS Score:8.4

    Affected Products

    Vendor
    Dlink
    Product
    Dir-2640-us
    Vendor
    Dlink
    Product
    Dir-2640-us Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High