CVE-2021-33259
CVE-2021-33259 is a medium-severity vulnerability in D-link Dir-868lw Firmware with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v2: 5.0
- EPSS exploit prediction: 2% (77th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-306
- Affected product: D-link Dir-868lw Firmware
- Published:
- Last modified:
Description
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
Frequently asked questions
- What is CVE-2021-33259?
- Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
- How severe is CVE-2021-33259?
- CVE-2021-33259 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2021-33259 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (77th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-33259?
- CVE-2021-33259 affects D-link Dir-868lw Firmware. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-33259?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-33259 published?
- CVE-2021-33259 was published on 2021-10-31 and last updated on 2026-07-09.
References
- https://github.com/jayus0821/uai-poc/blob/main/D-Link/DIR-868L/webaccess_UAI.md
- https://www.dlink.com/en/security-bulletin/
Affected products (1)
- cpe:2.3:o:d-link:dir-868lw_firmware:1.12b:*:*:*:*:*:*:*
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
- CVE-2026-59971 — Critical (CVSS 10.0): MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to…
- CVE-2026-80462 — Critical (CVSS 10.0): A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to…
- CVE-2026-75754 — Critical (CVSS 10.0): Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in…
- CVE-2026-70352 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →