CVE-2021-28844: Null Pointer Dereference
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to applycgi via a dographauth action without a sessionid key.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28844?
CVE-2021-28844 is a null pointer dereference vulnerability that exists in TRENDnet TEW-755AP, TEW-755AP2KAC, TEW-821DAP2KAC, and TEW-825DAP firmware versions 1.11B03.
How does CVE-2021-28844 affect TRENDnet TEW-755AP?
CVE-2021-28844 allows an attacker to cause a null pointer dereference by sending a specially crafted POST request to apply_cgi without a session_id key.
What is the severity of CVE-2021-28844?
CVE-2021-28844 has a severity rating of 7.5 (high).
Is TRENDnet TEW-755AP2KAC affected by CVE-2021-28844?
Yes, TRENDnet TEW-755AP2KAC firmware version 1.11B03 is affected by CVE-2021-28844.
How can CVE-2021-28844 be fixed?
To fix CVE-2021-28844, it is recommended to update the affected firmware versions to a patched version provided by TRENDnet.