PT-2020-6514 · D Link · D-Link Dap-2020

Anthony Schneiter

+1

·

Published

2020-09-08

·

Updated

2023-11-08

·

CVE-2021-27249

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DAP-2020 version 1.01rc001
Description The issue is related to the implementation of the WEB CmdFileList() function in the D-Link DAP-2020 Wi-Fi access point's firmware, which fails to neutralize special elements used in operating system commands when processing CGI scripts. This allows an attacker to execute arbitrary code on the device. The flaw exists due to the lack of proper validation of a user-supplied string before using it to execute a system call, enabling an attacker to execute code in the context of root. No authentication is required to exploit this issue.
Recommendations For D-Link DAP-2020 version 1.01rc001, consider disabling the WEB CmdFileList() function as a temporary workaround until a patch is available. Restrict access to CGI scripts to minimize the risk of exploitation. Avoid using user-supplied strings in system calls until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05759
CVE-2021-27249
ZDI-21-204

Affected Products

D-Link Dap-2020