An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1361 | third party advisory exploit |