Vulnerability Description
D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerability exists in the web interface "/cgi-bin/New_GUI/Igmp.asp". Authenticated remote attackers can trigger this vulnerability by sending a long string in parameter 'igmpsnoopEnable' via an HTTP request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dsl-3782 Firmware | eu_1.01 |
| Dlink | Dsl-3782 | - |
Related Weaknesses (CWE)
References
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1PatchVendor Advisory
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1PatchVendor Advisory
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
FAQ
What is CVE-2021-40284?
CVE-2021-40284 is a vulnerability with a CVSS score of 6.5 (MEDIUM). D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerability exists in the web interface "/cgi-bin/New_GUI/Igmp.asp". Authenticated remote...
How severe is CVE-2021-40284?
CVE-2021-40284 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40284?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dsl-3782 Firmware, Dlink Dsl-3782.