dir-2640-us_firmware vulnerabilities
CVEs whose affected-version data names the dir-2640-us_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2021-34204Medium· 6.8D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials
D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all dev…
CVE-2021-34203High· 8.1D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password…
CVE-2021-34201High· 7.1D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow
D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, caus…
CVE-2021-34202High· 7.8There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04
There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04. Ordinary permissions can be elevated to administrator permissions, resulting in local arbitrary code execution. An attacker can combin…