Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-28838


Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.


Published

2021-08-10T18:15:07.137

Last Modified

2024-11-21T06:00:18.183

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dap-2310_firmware ≤ 2.10rc039 Yes
Hardware dlink dap-2310 - No
Operating System dlink dap-2330_firmware < 1.10rc036 Yes
Operating System dlink dap-2330_firmware 1.10rc036 Yes
Hardware dlink dap-2330 - No
Operating System dlink dap-2360_firmware ≤ 2.10rc055 Yes
Hardware dlink dap-2360 - No
Operating System dlink dap-2553_firmware < 3.10rc039 Yes
Operating System dlink dap-2553_firmware 3.10rc039 Yes
Hardware dlink dap-2553 - No
Operating System dlink dap-2660_firmware ≤ 1.15rc131b Yes
Hardware dlink dap-2660 - No
Operating System dlink dap-2690_firmware < 3.20rc115 Yes
Operating System dlink dap-2690_firmware 3.20rc115 Yes
Hardware dlink dap-2690 - No
Operating System dlink dap-2695_firmware ≤ 1.20rc093 Yes
Hardware dlink dap-2695 - No
Operating System dlink dap-3320_firmware < 1.05rc027 Yes
Operating System dlink dap-3320_firmware 1.05rc027 Yes
Hardware dlink dap-3320 - No
Operating System dlink dap-3662_firmware < 1.05rc069 Yes
Operating System dlink dap-3662_firmware 1.05rc069 Yes
Hardware dlink dap-3662 - No

References