Vulnerabilities > CVE-2021-44127 - Unspecified vulnerability in Dlink Dap-1360F1 Firmware 6.10

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
dlink
critical

Summary

In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

Vulnerable Configurations

Part Description Count
OS
Dlink
1
Hardware
Dlink
1