📦 Dir 3040 Firmware

by Dlink

🔍 What is Dir 3040 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-21913

CRITICAL CVSS 9.8 Sep 23, 2021

CVE-2021-21913 is a critical vulnerability in D-LINK DIR-3040 routers that allows unauthenticated attackers to execute arbitrary commands via the MQTT service in the WiFi Smart Mesh functionality. Thi...

CVE-2021-21820

CRITICAL CVSS 9.8 Jul 16, 2021

This vulnerability allows remote attackers to execute arbitrary code on D-LINK DIR-3040 routers due to a hard-coded password in the Libcli Test Environment. Attackers can send specially crafted networ...

CVE-2023-41229

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-3040 routers without authentication. Attackers can exploit a heap buffer overflow in the prog.cgi b...

CVE-2023-41217

HIGH CVSS 7.1 May 3, 2024

This vulnerability allows network-adjacent attackers with authentication to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exists in the prog.cgi binary's handling of HNAP request...

CVE-2022-1262

HIGH CVSS 7.8 Apr 11, 2022

CVE-2022-1262 is a command injection vulnerability in the protest binary that allows authenticated attackers with CLI access to execute arbitrary commands with root privileges. This affects systems ru...

CVE-2021-21819

HIGH CVSS 7.2 Jul 16, 2021

This vulnerability allows remote attackers to execute arbitrary commands on D-LINK DIR-3040 routers by sending specially crafted network requests to the Libcli Test Environment. Attackers can gain ful...

CVE-2021-21817

HIGH CVSS 7.5 Jul 16, 2021

This vulnerability in D-LINK DIR-3040 routers allows attackers to obtain sensitive information through specially crafted network requests to the Zebra IP Routing Manager. Attackers can exploit this wi...

CVE-2024-5294

MEDIUM CVSS 6.5 May 23, 2024

This vulnerability allows network-adjacent attackers to cause a denial-of-service condition on D-Link DIR-3040 routers by exploiting a memory leak in the prog.cgi program. No authentication is require...

CVE-2023-41226

MEDIUM CVSS 6.8 May 3, 2024

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exists in the prog.cgi binary's handling of HNAP requ...

CVE-2023-41228

MEDIUM CVSS 6.8 May 3, 2024

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exists in the prog.cgi binary that handles HNAP reque...

CVE-2023-41219

MEDIUM CVSS 6.8 May 3, 2024

This is a stack-based buffer overflow vulnerability in D-Link DIR-3040 routers that allows authenticated attackers on the local network to execute arbitrary code with root privileges. The vulnerabilit...

CVE-2023-41221

MEDIUM CVSS 6.8 May 3, 2024

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exists in the prog.cgi binary that handles HNAP reque...

CVE-2023-41224

MEDIUM CVSS 6.8 May 3, 2024

This CVE describes a stack-based buffer overflow vulnerability in D-Link DIR-3040 routers that allows authenticated attackers on the local network to execute arbitrary code with root privileges. The v...