The US government warns of security flaws in the D-Link router: patch now or possibly pay the price

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities found in some D-Link routers to its Known Exploited Vulnerabilities (KEV) database, meaning there is evidence of exploitation in the wild.

The two vulnerabilities are tracked as CVE-20214-100005 and CVE-2021-40655. The former is a cross-site request forgery (CSRF) error found in D-Link DIR-600 routers, while the latter is an information disclosure error found in D-Link DIR-605 routers . The former allows threat actors to change router configurations, while the latter allows for credential theft.