Exploited Known exploited (KEV) CVE-2021-40655

Retire it rather than fix it — the instruction for D-Link routers past their life

D-Link DIR-605 Router Added to KEV May 16, 2024 Federal remediation due 2024-06-06

For the information disclosure flaw in the D-Link DIR-605 router, CISA called not for a fix but for the equipment to be retired and replaced, because every associated hardware revision had reached end of life or end of service.

Key facts

  • CVE IDCVE-2021-40655
  • Affected (vendor / product)D-Link DIR-605 Router
  • CWECWE-863
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2024-06-06 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2021-40655 is an information disclosure vulnerability in D-Link DIR-605 routers.
  • A forged post request aimed at the /getcfg.php page will yield up a username and a password.
  • The required action is that the equipment be retired and something else put in its place, following the vendor.
  • The instruction gives its reason: these are legacy products and all associated hardware revisions have reached end of life or end of service.
  • Listed 16 May 2024 with a due date of 6 June, a window of twenty-one days; among the 1,579 entries without an article this site holds as of 2026-09-05, four share this exact wording.

1No fix among the options

The six entries so far all asked, to varying degrees, for something to be fixed. This one does not. What it asks for is the equipment to be retired and replaced. Repair does not appear as an option.

2The reason is written into the instruction

The aspectA typical entryThis entry, D-Link DIR-605
What is askedApply an update, or mitigateRetire and replace
Reason givenUsually noneLegacy products whose hardware revisions have all reached end of life or service
Possibility of a fixPresentNot offered
How it differs from discontinuing useNot stop using it, but replace it

Finding a reason in the required action field is itself unusual. Most entries write only what to do. Here the case for why an update is not the answer comes first, and the conclusion follows it.

3Few instructions rest on end of life

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,579The required action takes forty forms
Of those, instructions resting on end of life or end of service64 in totalAcross three forms, of 52, 8 and 4 entries
Entries sharing this exact wording4Among the least used of the forty

Instructions calling for replacement on grounds of end of life number 64 as a family. This exact wording, though, appears on four. It belongs to the individually written side.

4When there is no longer anyone to fix it

A vulnerability can be fixed for as long as the product lives. Once the product's life ends, the party that would fix it is gone. What remains is a choice between continuing to use it and replacing it.

The window was twenty-one days, listed 16 May 2024 and due 6 June. Replacement costs more time and money than a fix, yet the window stays at the most common twenty-one. The next article closes the series with an entry where the vendor instructions themselves did not exist.

Why it matters

A vulnerability remains fixable for as long as the product lives; once its life ends, the party that would fix it no longer exists. The instruction then cannot ask for an update and asks for retirement and replacement instead. That a reason appears in the required action field at all is exceptional, and shows the case for not updating had to be made first.

FAQ

Why replace rather than update?
The instruction states these are legacy products and that all associated hardware revisions have reached their end-of-life or end-of-service life cycle.
What kind of flaw is it?
An information disclosure flaw: a forged post request aimed at the /getcfg.php page yields up a username and a password.
Is this the same as discontinuing use?
No. The instruction asks for the equipment to be retired and replaced rather than simply taken out of use.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.