« Back to list

CVE-2021-28840

Status: ModifiedHigh (7.5)—

Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (9)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2021-28840",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-08-10T18:15:07.220",
  "references": [
    {
      "url": "https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.dlink.com/en/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.dlink.com/en/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability."
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad de Desreferencia de Puntero Null en D-Link DAP-2310 versión 2.07.RC031, DAP-2330 versión 1.07.RC028, DAP-2360 versión 2.07.RC043, DAP-2553 versión 3.06.RC027, DAP-2660 versión 1. 13.RC074, DAP-2690 versión 3.16.RC100, DAP-2695 versión 1.17.RC063, DAP-3320 versión 1.01.RC014 y DAP-3662 versión 1.01.RC022, en la función upload_config del binario sbin/httpd. Cuando el binario maneja la petición HTTP GET específica, el contenido en la variable upload_file es NULL en la función upload_config entonces el strncasecmp tomaría NULL como primer argumento, e incurriría en la vulnerabilidad de Desreferencia de Puntero Null"
    }
  ],
  "lastModified": "2026-06-17T03:46:58.327",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-2310_firmware:2.0.7.rc031:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BBA6F0B-083F-4772-AF62-9976FDA9B0AE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-2310:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8C5F3D97-3CFE-41B9-9C8B-832445EA92B0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-2330_firmware:1.07.rc028:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F69902B-ADBD-4B97-9BA2-3C198FD5B2AB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-2330:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9ABC8839-D62A-4AAB-A9D2-AFE95CBB9B17"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-2360_firmware:2.07.rc043:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B1E1F6E-BB52-4F5B-B2FC-9AFEA8039971"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-2360:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E7AE9A88-AD97-41A5-9847-4282788EBB1E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-2553_firmware:3.06.rc027:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0C8C853-352D-44EF-A311-BB1DDBB5401E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-2553:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "20BA9382-B0D4-4E7C-A198-067AA65AB190"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-2660_firmware:1.13.rc074:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA764CAB-2165-4E54-87B2-4011FEF1BE89"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-2660:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "41EFE653-296E-4E37-9DCC-BAF99C4AD2F3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-2690_firmware:3.16.rc100:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "290596AB-F094-4AAF-B974-435960328E26"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-2690:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3B827A81-49A8-4AFD-943A-3F359615E49D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-2695_firmware:1.17.rc063:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DE9E559-D849-4330-823A-649E7E335BD8"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-2695:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9039DA66-D624-4590-B236-101B775C5956"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-3320_firmware:1.01.rc014:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE90DE31-9674-4E8A-8B37-B168ED18762D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-3320:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "95D03B33-E8D6-4ED3-AED3-8FBDE80C74CB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dap-3662_firmware:1.01.rc022:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D51CFA61-E9F8-4D18-87C5-17A502235807"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dap-3662:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "07645866-3B61-46AB-85C6-ED86F1B0D47F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}