Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29379

Опубликовано: 12 апр. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 5.8
EPSS Средний

Описание

An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dlink:dir-802_firmware:*:*:*:*:*:*:*:*
Версия до 1.00b05 (включая)
cpe:2.3:h:dlink:dir-802:a1:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.30375
Средний

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

EPSS

Процентиль: 97%
0.30375
Средний

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-78