D-Link - Information Disclosure (CVE-2021-40655)
376Exploiting IPs reported
An informtion disclosure issue exists in D-Link product running the D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
CrowdSec analysis
CVE-2021-40655 is a vulnerability affecting certain D-Link products, where information disclosure can occur if a remote attacker forges requests to a specific configuration page.
CrowdSec has been tracking this vulnerability and its exploits since 10th of March 2025.
CrowdSec network observations suggest that most exploitation of CVE-2021-40655 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental. In addition, according to the CrowdSec network, attack volume against CVE-2021-40655 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.
Attackers typically attempt to exploit this issue by making requests to endpoints ending with /getcfg.php
.
Exploitation
Get real-time information about exploitation attempts and actors involved.
Protection
Find out relevant information to protect your stack against this CVE.
Blocklist
With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.
To increase your protection against this CVE, block exploitation attempts with this list of identified actors.