CVE-2021-28143: OS Command Injection
Published Mar 11, 2021
·Updated
/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).
Affected Software
3 affected components
Dlink Dir-841 Firmware=3.03
Dlink Dir-841 Firmware=3.04
Dlink Dir-841
Remediation
Event History
Mar 11, 2021
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28143?
CVE-2021-28143 has a medium severity rating due to the potential for authenticated command injection.
2
How do I fix CVE-2021-28143?
To mitigate CVE-2021-28143, update the D-Link DIR-841 firmware to version 3.05 or later.
3
Which versions of D-Link DIR-841 are affected by CVE-2021-28143?
CVE-2021-28143 affects D-Link DIR-841 firmware versions 3.03 and 3.04.
4
What is the potential impact of CVE-2021-28143?
CVE-2021-28143 allows an authenticated user to execute arbitrary commands on the device via crafted requests.
5
Are all D-Link DIR-841 devices vulnerable to CVE-2021-28143?
No, only devices running firmware versions 3.03 and 3.04 are vulnerable to CVE-2021-28143.