First published: Tue Nov 23 2021(Updated: )
Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to execute administrative actions.
Credit: cve_disclosure@tech.gov.sg cve_disclosure@tech.gov.sg
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
D-Link DWR-932C | <=1.0.0.4 | |
D-Link DWR-932C | =revision_e | |
D-Link DWR-932C | <=1.0.0.4 | |
D-Link DWR-932C | =revision_e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42783 is classified as a critical vulnerability due to the potential for unauthenticated administrative actions.
To fix CVE-2021-42783, update the D-Link DWR-932C E1 firmware to the latest version that addresses this vulnerability.
Users of the D-Link DWR-932C E1 firmware versions up to 1.0.0.4 are affected by CVE-2021-42783.
An attacker can execute administrative actions without authentication due to the missing authentication in the specified CGI.
There is no specific workaround for CVE-2021-42783; the recommended action is to update the firmware to mitigate the risk.