Vulnerabilities > CVE-2021-29294 - NULL Pointer Dereference vulnerability in Dlink Dsl-2740R Firmware Uk1.01

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
dlink
CWE-476

Summary

Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the send_hnap_unauthorized function. It could be triggered by sending crafted POST request to /HNAP1/. NOTE: The DSL-2740R and all hardware revisions are considered End of Life and as such this issue will not be patched

Vulnerable Configurations

Part Description Count
OS
Dlink
1
Hardware
Dlink
1

Common Weakness Enumeration (CWE)