Vulnerability Description
Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dap-2310 Firmware | <= 2.10rc039 |
| Dlink | Dap-2310 | - |
| Dlink | Dap-2330 Firmware | < 1.10rc036 |
| Dlink | Dap-2330 | - |
| Dlink | Dap-2360 Firmware | <= 2.10rc055 |
| Dlink | Dap-2360 | - |
| Dlink | Dap-2553 Firmware | < 3.10rc039 |
| Dlink | Dap-2553 | - |
| Dlink | Dap-2660 Firmware | <= 1.15rc131b |
| Dlink | Dap-2660 | - |
| Dlink | Dap-2690 Firmware | < 3.20rc115 |
| Dlink | Dap-2690 | - |
| Dlink | Dap-2695 Firmware | <= 1.20rc093 |
| Dlink | Dap-2695 | - |
| Dlink | Dap-3320 Firmware | < 1.05rc027 |
| Dlink | Dap-3320 | - |
| Dlink | Dap-3662 Firmware | < 1.05rc069 |
| Dlink | Dap-3662 | - |
Related Weaknesses (CWE)
References
- https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdfExploitThird Party Advisory
- https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdfThird Party Advisory
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
- https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdfExploitThird Party Advisory
- https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdfThird Party Advisory
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
FAQ
What is CVE-2021-28838?
CVE-2021-28838 is a vulnerability with a CVSS score of 7.5 (HIGH). Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC...
How severe is CVE-2021-28838?
CVE-2021-28838 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28838?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dap-2310 Firmware, Dlink Dap-2310, Dlink Dap-2330 Firmware, Dlink Dap-2330, Dlink Dap-2360 Firmware.