// For flags

CVE-2021-28838

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.

Una vulnerabilidad de Desreferencia de Puntero Null en D-Link DAP-2310 versión 2,10RC039, DAP-2330 versión 1.10RC036 BETA, DAP-2360 versión 2.10RC055, DAP-2553 versión 3.10rc039 BETA, DAP-2660 versión 1. 15rc131b, DAP-2690 versión 3.20RC115 BETA, DAP-2695 versión 1.20RC093, DAP-3320 versión 1.05RC027 BETA y DAP-3662 versión 1.05rc069, en el binario sbin/httpd. El bloqueo se produce en la operación "atoi" cuando es enviado un paquete de red específico al binario httpd

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-03-19 CVE Reserved
  • 2021-08-10 CVE Published
  • 2024-04-25 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-476: NULL Pointer Dereference
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dlink
Search vendor "Dlink"
Dap-2310 Firmware
Search vendor "Dlink" for product "Dap-2310 Firmware"
<= 2.10rc039
Search vendor "Dlink" for product "Dap-2310 Firmware" and version " <= 2.10rc039"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-2310
Search vendor "Dlink" for product "Dap-2310"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2330 Firmware
Search vendor "Dlink" for product "Dap-2330 Firmware"
< 1.10rc036
Search vendor "Dlink" for product "Dap-2330 Firmware" and version " < 1.10rc036"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-2330
Search vendor "Dlink" for product "Dap-2330"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2330 Firmware
Search vendor "Dlink" for product "Dap-2330 Firmware"
1.10rc036
Search vendor "Dlink" for product "Dap-2330 Firmware" and version "1.10rc036"
beta
Affected
in Dlink
Search vendor "Dlink"
Dap-2330
Search vendor "Dlink" for product "Dap-2330"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2360 Firmware
Search vendor "Dlink" for product "Dap-2360 Firmware"
<= 2.10rc055
Search vendor "Dlink" for product "Dap-2360 Firmware" and version " <= 2.10rc055"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-2360
Search vendor "Dlink" for product "Dap-2360"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2553 Firmware
Search vendor "Dlink" for product "Dap-2553 Firmware"
< 3.10rc039
Search vendor "Dlink" for product "Dap-2553 Firmware" and version " < 3.10rc039"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-2553
Search vendor "Dlink" for product "Dap-2553"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2553 Firmware
Search vendor "Dlink" for product "Dap-2553 Firmware"
3.10rc039
Search vendor "Dlink" for product "Dap-2553 Firmware" and version "3.10rc039"
beta
Affected
in Dlink
Search vendor "Dlink"
Dap-2553
Search vendor "Dlink" for product "Dap-2553"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2660 Firmware
Search vendor "Dlink" for product "Dap-2660 Firmware"
<= 1.15rc131b
Search vendor "Dlink" for product "Dap-2660 Firmware" and version " <= 1.15rc131b"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-2660
Search vendor "Dlink" for product "Dap-2660"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2690 Firmware
Search vendor "Dlink" for product "Dap-2690 Firmware"
< 3.20rc115
Search vendor "Dlink" for product "Dap-2690 Firmware" and version " < 3.20rc115"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-2690
Search vendor "Dlink" for product "Dap-2690"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2690 Firmware
Search vendor "Dlink" for product "Dap-2690 Firmware"
3.20rc115
Search vendor "Dlink" for product "Dap-2690 Firmware" and version "3.20rc115"
beta
Affected
in Dlink
Search vendor "Dlink"
Dap-2690
Search vendor "Dlink" for product "Dap-2690"
--
Safe
Dlink
Search vendor "Dlink"
Dap-2695 Firmware
Search vendor "Dlink" for product "Dap-2695 Firmware"
<= 1.20rc093
Search vendor "Dlink" for product "Dap-2695 Firmware" and version " <= 1.20rc093"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-2695
Search vendor "Dlink" for product "Dap-2695"
--
Safe
Dlink
Search vendor "Dlink"
Dap-3320 Firmware
Search vendor "Dlink" for product "Dap-3320 Firmware"
< 1.05rc027
Search vendor "Dlink" for product "Dap-3320 Firmware" and version " < 1.05rc027"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-3320
Search vendor "Dlink" for product "Dap-3320"
--
Safe
Dlink
Search vendor "Dlink"
Dap-3320 Firmware
Search vendor "Dlink" for product "Dap-3320 Firmware"
1.05rc027
Search vendor "Dlink" for product "Dap-3320 Firmware" and version "1.05rc027"
beta
Affected
in Dlink
Search vendor "Dlink"
Dap-3320
Search vendor "Dlink" for product "Dap-3320"
--
Safe
Dlink
Search vendor "Dlink"
Dap-3662 Firmware
Search vendor "Dlink" for product "Dap-3662 Firmware"
< 1.05rc069
Search vendor "Dlink" for product "Dap-3662 Firmware" and version " < 1.05rc069"
-
Affected
in Dlink
Search vendor "Dlink"
Dap-3662
Search vendor "Dlink" for product "Dap-3662"
--
Safe
Dlink
Search vendor "Dlink"
Dap-3662 Firmware
Search vendor "Dlink" for product "Dap-3662 Firmware"
1.05rc069
Search vendor "Dlink" for product "Dap-3662 Firmware" and version "1.05rc069"
beta
Affected
in Dlink
Search vendor "Dlink"
Dap-3662
Search vendor "Dlink" for product "Dap-3662"
--
Safe