CVE-2021-27342
MEDIUM 5.9EPSS 4.6%
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack
- CVSS v3.1
- 5.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 4.56% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2021-05-17
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- guywhataguy/D-Link-CVE-2021-27342-exploit15★ · 2021-05-15
- mavlevin/D-Link-CVE-2021-27342-exploit15★ · 2021-05-15