7.5
Advisory Published
Updated

CVE-2022-38873

First published: Tue Dec 20 2022(Updated: )

D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta and earlier, DAP-3662 v1.05rc047 and earlier allows attackers to cause a Denial of Service (DoS) via uploading a crafted firmware after modifying the firmware header.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Dlink Dap-2310 Firmware<=2.10rc036
Dlink Dap-2310
Dlink Dap-2330 Firmware<=1.06rc020
Dlink Dap-2330
Dlink Dap-2360 Firmware<=2.10rc050
Dlink Dap-2360
Dlink Dap-2553 Firmware<=3.10rc031
Dlink Dap-2553
Dlink Dap-2660 Firmware<=1.15rc093
Dlink Dap-2660
Dlink Dap-2690 Firmware<=3.20rc106
Dlink Dap-2690
Dlink Dap-2695 Firmware<1.20rc119
Dlink Dap-2695 Firmware=1.20rc119-beta31
Dlink Dap-2695
Dlink Dap-3320 Firmware<1.05rc027
Dlink Dap-3320 Firmware=1.05rc027-beta
Dlink Dap-3320
Dlink Dap-3662 Firmware<=1.05rc047
Dlink Dap-3662

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-38873?

    The severity of CVE-2022-38873 is high with a severity value of 7.5.

  • Which D-Link devices are affected by CVE-2022-38873?

    D-Link devices DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2660, DAP-2690, DAP-2695, DAP-3320, and DAP-3662 are affected by CVE-2022-38873.

  • What is the affected firmware version for D-Link DAP-2310?

    The affected firmware version for D-Link DAP-2310 is up to and including 2.10rc036.

  • Is D-Link DAP-2695 vulnerable to CVE-2022-38873?

    No, D-Link DAP-2695 is not vulnerable to CVE-2022-38873.

  • Where can I find more information about CVE-2022-38873?

    More information about CVE-2022-38873 can be found at the following references: [Link 1](https://github.com/Yuhao-W/BUG--D-Link--Firmware-Update-Vulnerabilities/blob/main/README.md), [Link 2](https://www.dlink.com/en/security-bulletin/).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203