CVE-2021-28839: Null Pointer Dereference
Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the uploadcertificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the uploadcertificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28839?
CVE-2021-28839 is a Null Pointer Dereference vulnerability in certain D-Link devices.
Which D-Link devices are affected by CVE-2021-28839?
D-Link DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2660, DAP-2690, DAP-2695, DAP-3320, and DAP-3662 are affected by CVE-2021-28839.
What is the severity of CVE-2021-28839?
CVE-2021-28839 has a severity rating of 7.5 (High).
How does CVE-2021-28839 occur?
CVE-2021-28839 occurs when there is a null pointer dereference in the upload_certificate function of the affected devices.
Where can I find more information about CVE-2021-28839?
You can find more information about CVE-2021-28839 in the following references: [Link 1](https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf), [Link 2](https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf), [Link 3](https://www.dlink.com/en/security-bulletin/).