PT-2024-1618 · D Link · D-Link Dap-1650

Exodus Intelligence

·

Published

2024-01-25

·

Updated

2024-01-31

·

CVE-2024-23624

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DAP-1650 (affected versions not specified)
Description A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root. The vulnerability is related to incorrect input validation when processing UPnP SUBSCRIBE messages, allowing a remote attacker to execute arbitrary commands using specially crafted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-01285
CVE-2024-23624

Affected Products

D-Link Dap-1650