Vulnerability Description
A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receives a carefully constructed HTTP request, it will crash and exit due to a null pointer reference, leading to a denial of service attack to the device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dap-1513 Firmware | 1.01 |
| Dlink | Dap-1513 | - |
Related Weaknesses (CWE)
References
- https://docs.google.com/document/d/1qTpwAg7B5E4mqkBzijjuoOWWnf3OE1HXIKBv7OcS8Mc/Permissions Required
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10396Vendor Advisory
- https://www.dlink.com/enProduct
- https://www.dlink.com/en/security-bulletin/Product
FAQ
What is CVE-2024-36832?
CVE-2024-36832 is a vulnerability with a CVSS score of 7.5 (HIGH). A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /...
How severe is CVE-2024-36832?
CVE-2024-36832 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36832?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dap-1513 Firmware, Dlink Dap-1513.