CVE-2021-28842: Null Pointer Dereference
Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial os service by sending the POST request to applycgi via action dographauth without loginname key.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28842?
CVE-2021-28842 is a Null Pointer Deference vulnerability that exists in TRENDnet TEW-755AP, TEW-755AP2KAC, TEW-821DAP2KAC, and TEW-825DAP firmware versions 1.11B03.
How does CVE-2021-28842 impact the affected software?
CVE-2021-28842 could allow a remote malicious user to cause a denial of service by sending a POST request to apply_cgi via action do_graph_auth without the login_name key.
What is the severity of CVE-2021-28842?
CVE-2021-28842 has a severity value of 7.5, which is considered high.
How can I fix CVE-2021-28842?
To fix CVE-2021-28842, users should update their TRENDnet TEW-755AP, TEW-755AP2KAC, TEW-821DAP2KAC, and TEW-825DAP firmware to version 1.11B04 or later.
Where can I find more information about CVE-2021-28842?
More information about CVE-2021-28842 can be found at the following reference: [link](https://github.com/zyw-200/EQUAFL/blob/main/TRENDnet%20ticket.pdf).