CVE-2021-29379

HIGH

D-Link DIR-802 Firmware < 1.00b05 - OS Command Injection via UPnP SSDP M-SEARCH ST Field

Title source: llm
STIX 2.1

Description

An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://www.dlink.com/en/security-bulletin/
Exploit, Third Party Advisory x_refsource_misc
https://cool-y.github.io/2021/03/02/DIR-802-OS-Command-Injection

Scores

CVSS v3 8.8
EPSS 0.3038
EPSS Percentile 96.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
dlink/dir-802_firmware < 1.00b05
Published Apr 12, 2021
Tracked Since Feb 18, 2026