CVE-2021-28839
Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Published:Aug 10, 2021
Last Modified:Nov 21, 2024
EPS:Aug 10, 2021
EPSS Score:0.00564
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Dlink
Product
Dap-2310
Dlink
Dap-2310
Vendor
Dlink
Product
Dap-2310 Firmware
Dlink
Dap-2310 Firmware
Vendor
Dlink
Product
Dap-2330
Dlink
Dap-2330
Vendor
Dlink
Product
Dap-2330 Firmware
Dlink
Dap-2330 Firmware
Vendor
Dlink
Product
Dap-2360
Dlink
Dap-2360
Vendor
Dlink
Product
Dap-2360 Firmware
Dlink
Dap-2360 Firmware
Vendor
Dlink
Product
Dap-2553
Dlink
Dap-2553
Vendor
Dlink
Product
Dap-2553 Firmware
Dlink
Dap-2553 Firmware
Vendor
Dlink
Product
Dap-2660
Dlink
Dap-2660
Vendor
Dlink
Product
Dap-2660 Firmware
Dlink
Dap-2660 Firmware
Vendor
Dlink
Product
Dap-2690
Dlink
Dap-2690
Vendor
Dlink
Product
Dap-2690 Firmware
Dlink
Dap-2690 Firmware
Vendor
Dlink
Product
Dap-2695
Dlink
Dap-2695
Vendor
Dlink
Product
Dap-2695 Firmware
Dlink
Dap-2695 Firmware
Vendor
Dlink
Product
Dap-3320
Dlink
Dap-3320
Vendor
Dlink
Product
Dap-3320 Firmware
Dlink
Dap-3320 Firmware
Vendor
Dlink
Product
Dap-3662
Dlink
Dap-3662
Vendor
Dlink
Product
Dap-3662 Firmware
Dlink
Dap-3662 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
