---
id: CVE-2021-34203
title: D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control
summary: >-
  D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router
  ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way
  of whole network monitoring, and this function uses the original default
  password…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-1188
vendor: dlink
product: dir-2640-us_firmware
affected:
  - dir-2640-us_firmware = 1.01b04
published: '2021-06-16'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-34203'
references:
  - url: 'https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-34203'
    label: cve@mitre.org
  - url: 'https://www.dlink.com/en/security-bulletin/'
    label: cve@mitre.org
  - url: 'http://d-link.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://dir-2640-us.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-34203'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.dlink.com/en/security-bulletin/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01195
epssPercentile: 0.66696
ingestedAt: '2026-07-06T01:08:16.760Z'
---

## Overview

D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password and port. An attacker can easily use telnet to log in, modify routing information, monitor the traffic of all devices under the router, hijack DNS and phishing attacks. In addition, this interface is likely to be questioned by customers as a backdoor, because the interface should not be exposed.

## Affected

- `dir-2640-us_firmware = 1.01b04`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
