← Back

CVE-2021-28839

nvd nist
Published: Aug 10, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

Affected (9)

9 products
Dap 2310 Firmware
Dap 2330 Firmware
Dap 2360 Firmware
Dap 2553 Firmware
Dap 2660 Firmware
Dap 2690 Firmware
Dap 2695 Firmware
Dap 3320 Firmware
Dap 3662 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.0.7.rc031
Running on/withPlatform Versions
Dlink
Dap 2310
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.07.rc028
Running on/withPlatform Versions
Dlink
Dap 2330
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.07.rc043
Running on/withPlatform Versions
Dlink
Dap 2360
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.06.rc027
Running on/withPlatform Versions
Dlink
Dap 2553
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.13.rc074
Running on/withPlatform Versions
Dlink
Dap 2660
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.16.rc100
Running on/withPlatform Versions
Dlink
Dap 2690
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.17.rc063
Running on/withPlatform Versions
Dlink
Dap 2695
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.01.rc014
Running on/withPlatform Versions
Dlink
Dap 3320
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.01.rc022
Running on/withPlatform Versions
Dlink
Dap 3662
All versions

References (6)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.