PT-2021-6117 · D Link · D-Link Dir-X1860

Constantinos Kolias

+2

·

Published

2021-09-01

·

Updated

2024-02-14

·

CVE-2021-41442

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-X1860 versions prior to v1.10WWB09 Beta
Description The issue is related to a web application vulnerability in the D-Link DIR-X1860 Wi-Fi router's firmware, specifically concerning inadequate handling of HTTP requests. This can be exploited by a remote attacker to send a hidden HTTP request, also known as an HTTP Request Smuggling attack, using specially crafted HTTP packets. The attack allows a remote unauthenticated attacker to perform a Denial of Service (DoS) on the web application by sending a specific HTTP packet.
Recommendations For versions prior to v1.10WWB09 Beta, update to v1.10WWB09 Beta or later to resolve the issue. As a temporary workaround, consider restricting access to the web application to minimize the risk of exploitation. Avoid using the vulnerable web application until the issue is resolved.

Fix

Improper Resource Release

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

BDU:2022-00863
CVE-2021-41442

Affected Products

D-Link Dir-X1860