PT-2021-18163 · D Link · D-Link Dir-825

·

CVE-2021-29296

·

Published

2021-08-10

·

Updated

2024-08-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: D-Link DIR-825 version 2.10b02
Description: The issue is a Null Pointer Dereference vulnerability that could allow a remote malicious user to cause a denial of service. This can be triggered by sending an HTTP request with the URL /vct wan, which causes the sbin/httpd to invoke the strchr function with NULL as the first argument, leading to a segmentation fault.
Recommendations: For D-Link DIR-825 version 2.10b02, since the device is considered End of Life and the issue will not be patched, consider replacing the device with a supported model to mitigate the risk of exploitation. As a temporary workaround, restrict access to the /vct wan URL to minimize the risk of denial of service attacks.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29296

Affected Products

D-Link Dir-825