D-Link Dap-2020 vulnerabilities

7 known vulnerabilities affecting d-link/dap-2020.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2021-34862HIGHCVSS 8.8v1.01rc0012021-10-25
CVE-2021-34862 [HIGH] CWE-121 CVE-2021-34862: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the var:menu parameter provided to the webproc endpoint. The issue results from the lack of proper v
cvelistv5nvd
CVE-2021-34861HIGHCVSS 8.8v1.01rc0012021-10-25
CVE-2021-34861 [HIGH] CWE-121 CVE-2021-34861: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the webproc endpoint, which listens on TCP port 80 by default. The issue results from the lack of proper validation
cvelistv5nvd
CVE-2021-34863HIGHCVSS 8.8v1.01rc0012021-10-25
CVE-2021-34863 [HIGH] CWE-121 CVE-2021-34863: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the var:page parameter provided to the webproc endpoint. The issue results from the lack of proper v
cvelistv5nvd
CVE-2021-34860MEDIUMCVSS 6.5v1.01rc0012021-10-25
CVE-2021-34860 [MEDIUM] CWE-22 CVE-2021-34860: This vulnerability allows network-adjacent attackers to disclose sensitive information on affected i This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the getpage parameter provided to the webproc endpoint. The issue results from the lack of
cvelistv5nvd
CVE-2021-27248HIGHCVSS 8.8vv1.01rc0012021-04-14
CVE-2021-27248 [HIGH] CWE-121 CVE-2021-27248: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of CGI scripts. When parsing the getpage parameter, the process does not properly valida
cvelistv5nvd
CVE-2021-27249HIGHCVSS 8.8vv1.01rc0012021-04-14
CVE-2021-27249 [HIGH] CWE-78 CVE-2021-27249: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of CGI scripts. The issue results from the lack of proper validation of a user-supplied s
cvelistv5nvd
CVE-2021-27250MEDIUMCVSS 6.5vv1.01rc0012021-04-14
CVE-2021-27250 [MEDIUM] CWE-73 CVE-2021-27250: This vulnerability allows network-adjacent attackers to disclose sensitive information on affected i This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of CGI scripts. When parsing the errorpage request parameter, the process does
cvelistv5nvd