CVE-2021-42784: OS Command Injection in debug_fcgi in D-Link DWR-932C E1 Firmware 1.0.0.4
Published Nov 23, 2021
·Updated
OS Command Injection vulnerability in debugfcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform command injection via a crafted HTTP request.
Affected Software
4 affected components
Dlink Dwr-932c E1 Firmware<=1.0.0.4
Dlink Dwr-932c=revision_e
All of the following
Dlink Dwr-932c E1 Firmware<=1.0.0.4
Dlink Dwr-932c=revision_e
Remediation
Event History
Nov 23, 2021
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42784?
CVE-2021-42784 is a critical severity OS Command Injection vulnerability allowing remote code execution through crafted HTTP requests.
2
How do I fix CVE-2021-42784?
To fix CVE-2021-42784, update the D-Link DWR-932C E1 firmware to versions later than 1.0.0.4.
3
What devices are affected by CVE-2021-42784?
CVE-2021-42784 affects the D-Link DWR-932C E1 firmware version 1.0.0.4 and earlier.
4
Can CVE-2021-42784 be exploited remotely?
Yes, CVE-2021-42784 can be exploited remotely by sending specially crafted HTTP requests.
5
What are the potential impacts of CVE-2021-42784?
The potential impacts of CVE-2021-42784 include unauthorized access and full system compromise due to command injection.