First published: Tue Aug 10 2021(Updated: )
Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dap-2310 Firmware | =2.0.7.rc031 | |
Dlink Dap-2310 | ||
Dlink Dap-2330 Firmware | =1.07.rc028 | |
Dlink Dap-2330 | ||
Dlink Dap-2360 Firmware | =2.07.rc043 | |
Dlink Dap-2360 | ||
Dlink Dap-2553 Firmware | =3.06.rc027 | |
Dlink Dap-2553 | ||
Dlink Dap-2660 Firmware | =1.13.rc074 | |
Dlink Dap-2660 | ||
Dlink Dap-2690 Firmware | =3.16.rc100 | |
Dlink Dap-2690 | ||
Dlink Dap-2695 Firmware | =1.17.rc063 | |
Dlink Dap-2695 | ||
Dlink Dap-3320 Firmware | =1.01.rc014 | |
Dlink Dap-3320 | ||
Dlink Dap-3662 Firmware | =1.01.rc022 | |
Dlink Dap-3662 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28840 is a Null Pointer Dereference vulnerability that exists in D-Link DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2660, DAP-2690, DAP-2695, DAP-3320, and DAP-3662.
CVE-2021-28840 has a severity rating of 7.5 (High).
The following software versions are affected: D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014, and DAP-3662 1.01.RC022.
To fix CVE-2021-28840, it is recommended to update to the latest firmware version provided by D-Link.
You can find more information about CVE-2021-28840 on the D-Link security bulletin and GitHub references provided.