CVE-2021-28838
Dashboard / Vulnerabilities / CVE-2021-28838
CVE-2021-28838
Published: 10 Aug 2021Last Modified: 10 Mar 2026
Summary:
Details: Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.
References: , https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf, https://www.dlink.com/en/security-bulletin/, https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
