PT-2022-24602 · D Link · D-Link Dap-2310+8
Published
2022-12-20
·
Updated
2022-12-29
·
CVE-2022-38873
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DAP-2310 versions 2.10rc036 and earlier
D-Link DAP-2330 versions 1.06rc020 and earlier
D-Link DAP-2360 versions 2.10rc050 and earlier
D-Link DAP-2553 versions 3.10rc031 and earlier
D-Link DAP-2660 versions 1.15rc093 and earlier
D-Link DAP-2690 versions 3.20rc106 and earlier
D-Link DAP-2695 versions 1.20rc119 beta31 and earlier
D-Link DAP-3320 versions 1.05rc027 beta and earlier
D-Link DAP-3662 versions 1.05rc047 and earlier
Description
The issue allows attackers to cause a Denial of Service (DoS) via uploading a crafted firmware after modifying the firmware header.
Recommendations
For D-Link DAP-2310 versions 2.10rc036 and earlier, update to a version later than 2.10rc036 to resolve the issue.
For D-Link DAP-2330 versions 1.06rc020 and earlier, update to a version later than 1.06rc020 to resolve the issue.
For D-Link DAP-2360 versions 2.10rc050 and earlier, update to a version later than 2.10rc050 to resolve the issue.
For D-Link DAP-2553 versions 3.10rc031 and earlier, update to a version later than 3.10rc031 to resolve the issue.
For D-Link DAP-2660 versions 1.15rc093 and earlier, update to a version later than 1.15rc093 to resolve the issue.
For D-Link DAP-2690 versions 3.20rc106 and earlier, update to a version later than 3.20rc106 to resolve the issue.
For D-Link DAP-2695 versions 1.20rc119 beta31 and earlier, update to a version later than 1.20rc119 beta31 to resolve the issue.
For D-Link DAP-3320 versions 1.05rc027 beta and earlier, update to a version later than 1.05rc027 beta to resolve the issue.
For D-Link DAP-3662 versions 1.05rc047 and earlier, update to a version later than 1.05rc047 to resolve the issue.
As a temporary workaround, consider restricting the ability to upload firmware to minimize the risk of exploitation.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dap-2310
D-Link Dap-2330
D-Link Dap-2360
D-Link Dap-2553
D-Link Dap-2660
D-Link Dap-2690
D-Link Dap-2695
D-Link Dap-3320
D-Link Dap-3662