PT-2021-17954 · D Link · D-Link Dap-2360+8

Published

2021-08-10

·

Updated

2021-08-17

·

CVE-2021-28838

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: D-Link DAP-2310 version 2,10RC039 D-Link DAP-2330 version 1.10RC036 BETA D-Link DAP-2360 version 2.10RC055 D-Link DAP-2553 version 3.10rc039 BETA D-Link DAP-2660 version 1.15rc131b D-Link DAP-2690 version 3.20RC115 BETA D-Link DAP-2695 version 1.20RC093 D-Link DAP-3320 version 1.05RC027 BETA D-Link DAP-3662 version 1.05rc069
Description: A null pointer dereference vulnerability exists in the sbin/httpd binary of the affected D-Link devices. The crash occurs at the atoi operation when a specific network package is sent to the httpd binary.
Recommendations: For D-Link DAP-2310 version 2,10RC039, update to a newer version that contains a fix for this issue. For D-Link DAP-2330 version 1.10RC036 BETA, update to a newer version that contains a fix for this issue. For D-Link DAP-2360 version 2.10RC055, update to a newer version that contains a fix for this issue. For D-Link DAP-2553 version 3.10rc039 BETA, update to a newer version that contains a fix for this issue. For D-Link DAP-2660 version 1.15rc131b, update to a newer version that contains a fix for this issue. For D-Link DAP-2690 version 3.20RC115 BETA, update to a newer version that contains a fix for this issue. For D-Link DAP-2695 version 1.20RC093, update to a newer version that contains a fix for this issue. For D-Link DAP-3320 version 1.05RC027 BETA, update to a newer version that contains a fix for this issue. For D-Link DAP-3662 version 1.05rc069, update to a newer version that contains a fix for this issue. As a temporary workaround, consider disabling the atoi operation in the sbin/httpd binary until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28838

Affected Products

D-Link Dap-2310
D-Link Dap-2330
D-Link Dap-2360
D-Link Dap-2553
D-Link Dap-2660
D-Link Dap-2690
D-Link Dap-2695
D-Link Dap-3320
D-Link Dap-3662