PT-2021-17956 · D Link · D-Link Dap-2360+8

Published

2021-08-10

·

Updated

2021-08-17

·

CVE-2021-28840

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: D-Link DAP-2310 version 2.07.RC031 D-Link DAP-2330 version 1.07.RC028 D-Link DAP-2360 version 2.07.RC043 D-Link DAP-2553 version 3.06.RC027 D-Link DAP-2660 version 1.13.RC074 D-Link DAP-2690 version 3.16.RC100 D-Link DAP-2695 version 1.17.RC063 D-Link DAP-3320 version 1.01.RC014 D-Link DAP-3662 version 1.01.RC022
Description: A Null Pointer Dereference vulnerability exists in the upload config function of the sbin/httpd binary. When the binary handles a specific HTTP GET request, the content in the upload file variable is NULL in the upload config function, then the strncasecmp function would take NULL as the first argument, and incur the Null Pointer Dereference vulnerability.
Recommendations: For D-Link DAP-2310 version 2.07.RC031, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-2330 version 1.07.RC028, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-2360 version 2.07.RC043, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-2553 version 3.06.RC027, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-2660 version 1.13.RC074, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-2690 version 3.16.RC100, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-2695 version 1.17.RC063, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-3320 version 1.01.RC014, consider disabling the upload config function in the sbin/httpd binary until a patch is available. For D-Link DAP-3662 version 1.01.RC022, consider disabling the upload config function in the sbin/httpd binary until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28840

Affected Products

D-Link Dap-2310
D-Link Dap-2330
D-Link Dap-2360
D-Link Dap-2553
D-Link Dap-2660
D-Link Dap-2690
D-Link Dap-2695
D-Link Dap-3320
D-Link Dap-3662