CVE Published: 30/12/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: tenable |
Vendor: n/a |
Product: Quagga Services on D-Link DIR-2640 Routers Status : PUBLISHED
CVE-2021-20132 Description
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the "admin" user, UID 0).