CVE-2021-28838

Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dap-2310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2310:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:dlink:dap-2330_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2330_firmware:1.10rc036:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2330:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dlink:dap-2360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2360:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:dlink:dap-2553_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2553_firmware:3.10rc039:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2553:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dlink:dap-2660_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2660:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:dlink:dap-2690_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2690_firmware:3.20rc115:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2690:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dlink:dap-2695_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2695:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:dlink:dap-3320_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-3320_firmware:1.05rc027:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-3320:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:dlink:dap-3662_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-3662_firmware:1.05rc069:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-3662:-:*:*:*:*:*:*:*

History

17 Aug 2021, 14:57

Type Values Removed Values Added
CPE cpe:2.3:o:dlink:dap-2330_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-3662_firmware:1.05rc069:beta:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-3662_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-3320_firmware:1.05rc027:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2310:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2553:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2695_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2660_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2553_firmware:3.10rc039:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-3320:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2660:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2360:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-3662:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2695:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2553_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-3320_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2690:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2690_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2330_firmware:1.10rc036:beta:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-2330:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dap-2690_firmware:3.20rc115:beta:*:*:*:*:*:*
CWE CWE-476
References (MISC) https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf - (MISC) https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf - Exploit, Third Party Advisory
References (MISC) https://www.dlink.com/en/security-bulletin/ - (MISC) https://www.dlink.com/en/security-bulletin/ - Vendor Advisory
References (MISC) https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf - (MISC) https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

10 Aug 2021, 18:30

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-10 18:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-28838

Mitre link : CVE-2021-28838

CVE.ORG link : CVE-2021-28838


JSON object : View

Products Affected

dlink

  • dap-2360_firmware
  • dap-2695_firmware
  • dap-2695
  • dap-2360
  • dap-2553_firmware
  • dap-2553
  • dap-2330
  • dap-2310_firmware
  • dap-2330_firmware
  • dap-2690_firmware
  • dap-2690
  • dap-2660_firmware
  • dap-3320
  • dap-2310
  • dap-2660
  • dap-3662_firmware
  • dap-3320_firmware
  • dap-3662
CWE
CWE-476

NULL Pointer Dereference