First published: Tue Aug 10 2021(Updated: )
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to apply_cgi via the lang action without a language key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trendnet Tew-755ap Firmware | =1.11b03 | |
TRENDnet TEW-755AP | ||
Trendnet Tew-755ap2kac Firmware | =1.11b03 | |
Trendnet Tew-755ap2kac | ||
Trendnet Tew-821dap2kac Firmware | =1.11b03 | |
Trendnet Tew-821dap2kac | ||
Trendnet Tew-825dap Firmware | =1.11b03 | |
Trendnet Tew-825dap |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28845 is a Null Pointer Dereference vulnerability that exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03.
CVE-2021-28845 could allow a remote malicious user to cause a denial of service by sending a POST request to apply_cgi via the lang action without a language key.
CVE-2021-28845 affects TRENDnet TEW-755AP firmware version 1.11B03, TEW-755AP2KAC firmware version 1.11B03, TEW-821DAP2KAC firmware version 1.11B03, and TEW-825DAP firmware version 1.11B03.
CVE-2021-28845 has a severity rating of 7.5 out of 10 (high severity).
Currently, there is no known fix available for CVE-2021-28845. It is recommended to follow the vendor's advisory and apply any patches or updates as soon as they become available.