Vulnerability Description
Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an authenticated user without the access privilege via unspecified vectors.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dap-1880Ac Firmware | <= 1.21 |
| Dlink | Dap-1880Ac | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU92898656/index.htmlThird Party Advisory
- https://www.dlink-jp.com/support/release/jvnvu92898656_dap-1880ac.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU92898656/index.htmlThird Party Advisory
- https://www.dlink-jp.com/support/release/jvnvu92898656_dap-1880ac.htmlVendor Advisory
FAQ
What is CVE-2021-20697?
CVE-2021-20697 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an authenticated user without the access privilege via u...
How severe is CVE-2021-20697?
CVE-2021-20697 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-20697?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dap-1880Ac Firmware, Dlink Dap-1880Ac.