CVE-2021-20696: OS Command Injection
Published Apr 26, 2021
·Updated
DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted request to a specific CGI program.
Affected Software
2 affected components
Dlink Dap-1880ac Firmware<=1.21
Dlink Dap-1880ac
Event History
Apr 26, 2021
CVE Published
via MITRE·12:20 AM
Data Sourced
via MITRE·12:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20696?
CVE-2021-20696 is rated as a medium severity vulnerability.
2
How do I fix CVE-2021-20696?
To fix CVE-2021-20696, update the DAP-1880AC firmware to version 1.22 or later.
3
Who is affected by CVE-2021-20696?
CVE-2021-20696 affects users running DAP-1880AC firmware version 1.21 and earlier.
4
What type of vulnerability is CVE-2021-20696?
CVE-2021-20696 is a command injection vulnerability that allows remote authenticated attackers to execute arbitrary OS commands.
5
Can CVE-2021-20696 be exploited remotely?
Yes, CVE-2021-20696 can be exploited remotely by sending a specially crafted request to the targeted device.