Description
Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Published: 2021-08-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-15493 Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
History

No history.

Subscriptions

Dlink Dap-2310 Dap-2310 Firmware Dap-2330 Dap-2330 Firmware Dap-2360 Dap-2360 Firmware Dap-2553 Dap-2553 Firmware Dap-2660 Dap-2660 Firmware Dap-2690 Dap-2690 Firmware Dap-2695 Dap-2695 Firmware Dap-3320 Dap-3320 Firmware Dap-3662 Dap-3662 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T21:55:11.566Z

Reserved: 2021-03-19T00:00:00.000Z

Link: CVE-2021-28839

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-10T18:15:07.180

Modified: 2024-11-21T06:00:18.343

Link: CVE-2021-28839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses