PT-2021-18161 · D Link · D-Link Dsl-2740E
Zyw
·
Published
2021-08-10
·
Updated
2024-08-03
·
CVE-2021-29294
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
D-Link DSL-2740R version UK 1.01
Description:
A Null Pointer Dereference issue exists, which could allow a remote malicious user to cause a denial of service via the
send hnap unauthorized function. This can be triggered by sending a crafted POST request to "/HNAP1/". The device is considered End of Life and will not be patched.Recommendations:
As a temporary workaround, consider disabling the
send hnap unauthorized function until a formal resolution can be applied, however, since the device is End of Life and will not receive a patch, this may be the only available mitigation measure. Restrict access to the "/HNAP1/" endpoint to minimize the risk of exploitation.Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dsl-2740E