An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T22:02:51.925Z

Reserved: 2021-03-29T00:00:00

Link: CVE-2021-29379

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-12T05:15:12.503

Modified: 2024-11-21T06:01:01.220

Link: CVE-2021-29379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.