Vulnerabilities > CVE-2021-44127 - Unspecified vulnerability in Dlink Dap-1360F1 Firmware

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
dlink
critical

Summary

In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

Vulnerable Configurations

Part Description Count
OS
Dlink
1
Hardware
Dlink
1