CVE-2021-28840: Null Pointer Dereference
Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the uploadconfig function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in uploadfile variable is NULL in the uploadconfig function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28840?
CVE-2021-28840 is a Null Pointer Dereference vulnerability that exists in D-Link DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2660, DAP-2690, DAP-2695, DAP-3320, and DAP-3662.
How severe is CVE-2021-28840?
CVE-2021-28840 has a severity rating of 7.5 (High).
Which software versions are affected by CVE-2021-28840?
The following software versions are affected: D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014, and DAP-3662 1.01.RC022.
How can I fix CVE-2021-28840?
To fix CVE-2021-28840, it is recommended to update to the latest firmware version provided by D-Link.
Where can I find more information about CVE-2021-28840?
You can find more information about CVE-2021-28840 on the D-Link security bulletin and GitHub references provided.