HIGH

CVE-2021-28143

CVSS v3

8

HIGH

EPSS Score

23.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).

Technical details

Published
3/11/2021

Frequently asked questions

What is CVE-2021-28143?

/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).

Is CVE-2021-28143 actively exploited?

Active exploitation of CVE-2021-28143 has not been confirmed. The EPSS score is 23.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-28143?

CVE-2021-28143 has a CVSS v3 base score of 8 (HIGH severity).

Is CVE-2021-28143 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.