CVE-2021-44127: Critical severity d-link dap-1360 firmware vulnerability
In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44127?
CVE-2021-44127 is considered to have a high severity due to the potential for remote command execution on the affected D-Link DAP-1360 devices.
How do I fix CVE-2021-44127?
To fix CVE-2021-44127, users should upgrade to a newer firmware version that is not vulnerable, specifically one later than v6.10.
What are the affected devices for CVE-2021-44127?
The affected device for CVE-2021-44127 is the D-Link DAP-1360 F1 firmware version 6.10 and earlier.
Can CVE-2021-44127 be exploited remotely?
Yes, CVE-2021-44127 can be exploited remotely by an authenticated attacker using the vulnerable 'file' parameter.
What type of attack is associated with CVE-2021-44127?
CVE-2021-44127 is associated with remote command execution attacks that allow attackers to execute arbitrary commands on the device.