← Vulnerability feed

Vulnerability record · CVE-2021-28839 · published 10 August 2021

CVE-2021-28839: Dlink dap-2310 firmware null pointer dereference vulnerability

Dlink · Dap 2310 Firmware

Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

7.5 CVSS 3.1 High EPSS 1.4% · top 29.1% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-28839 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-39749Dlink dap-2660 firmware classic buffer overflow vulnerabilityD-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET …EPSS 1.2%9.8CVE-2023-39750Dlink dap-2660 firmware classic buffer overflow vulnerabilityD-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a…EPSS 14%9.8CVE-2016-1558Dlink dap-3662 firmware memory buffer overflow vulnerabilityBuffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP…EPSS 9.1%7.5CVE-2022-38873Dlink dap-2310 firmware insufficient verification of data authenticity vulnerabilityD-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DA…EPSS 0.48%7.5CVE-2021-28838Dlink dap-2310 firmware null pointer dereference vulnerabilityNull pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1…EPSS 2.2%7.5CVE-2021-28840Dlink dap-2310 firmware null pointer dereference vulnerabilityNull Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 …EPSS 2.3%6.2CVE-2026-21525Windows Remote Access Connection Manager null pointer dereference DoSWindows Remote Access Connection Manager contains a null pointer dereference (CWE-476) that lets an unauthorized attacker deny service locally. The f…KEVEPSS 4.8%analysed

Source: NIST National Vulnerability Database (record CVE-2021-28839), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.