PT-2024-1618 · D Link · D-Link Dap-1650
Exodus Intelligence
·
Published
2024-01-25
·
Updated
2024-01-31
·
CVE-2024-23624
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DAP-1650 (affected versions not specified)
Description
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root. The vulnerability is related to incorrect input validation when processing UPnP SUBSCRIBE messages, allowing a remote attacker to execute arbitrary commands using specially crafted data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dap-1650