CVE-2021-41442
published 2022-02-09CVE-2021-41442: An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.55%
87.9th percentile
An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-x1860_firmware | <= 1.03 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
D-Link DIR-X1860 1.03 RevA1 HTTP Packet denial of service (SAP10283)
vuldb·2026-07-06·CVSS 7.5
CVE-2021-41442 [HIGH] D-Link DIR-X1860 1.03 RevA1 HTTP Packet denial of service (SAP10283)
A vulnerability identified as problematic has been detected in D-Link DIR-X1860 1.03 RevA1. Affected by this issue is some unknown functionality of the component HTTP Packet Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2021-41442. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
GHSA-4hrq-xfjw-8g7p: An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1
ghsa_unreviewed·2022-02-10
CVE-2021-41442 [HIGH] CWE-444 GHSA-4hrq-xfjw-8g7p: An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1
An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published