CVE-2021-28838 Details
Description
Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf | CVE | Third Party Advisory |
| https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf | CVE | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | CVE | Vendor Advisory |
| https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve2.pdf | [email protected] | Third Party Advisory |
| https://github.com/zyw-200/EQUAFL/blob/main/dlink-email-cve.pdf | [email protected] | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink dap-2310 firmware | <= 2.10rc039 |
CPE
Remediation
| |
| dlink dap-2310 | All versions |
CPE
Remediation
| |
| dlink dap-2330 firmware | < 1.10rc036 1.10rc036 beta |
CPE
Remediation
| |
| dlink dap-2330 | All versions |
CPE
Remediation
| |
| dlink dap-2360 firmware | <= 2.10rc055 |
CPE
Remediation
| |
| dlink dap-2360 | All versions |
CPE
Remediation
| |
| dlink dap-2553 firmware | < 3.10rc039 3.10rc039 beta |
CPE
Remediation
| |
| dlink dap-2553 | All versions |
CPE
Remediation
| |
| dlink dap-2660 firmware | <= 1.15rc131b |
CPE
Remediation
| |
| dlink dap-2660 | All versions |
CPE
Remediation
| |
| dlink dap-2690 firmware | < 3.20rc115 3.20rc115 beta |
CPE
Remediation
| |
| dlink dap-2690 | All versions |
CPE
Remediation
| |
| dlink dap-2695 firmware | <= 1.20rc093 |
CPE
Remediation
| |
| dlink dap-2695 | All versions |
CPE
Remediation
| |
| dlink dap-3320 firmware | < 1.05rc027 1.05rc027 beta |
CPE
Remediation
| |
| dlink dap-3320 | All versions |
CPE
Remediation
| |
| dlink dap-3662 firmware | < 1.05rc069 1.05rc069 beta |
CPE
Remediation
| |
| dlink dap-3662 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 17, 2021 | Initial Analysis | [email protected] |