PT-2024-1619 · D Link · D-Link Dap-1650
Exodus Intelligence
·
Published
2024-01-25
·
Updated
2024-01-31
·
CVE-2024-23625
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DAP-1650 (affected versions not specified)
Description
A command injection issue exists when handling UPnP SUBSCRIBE messages, allowing an unauthenticated attacker to gain command execution on the device as root. The vulnerability is related to incorrect input validation in the UPnP SUBSCRIBE Message Handler component. An attacker can exploit this issue by sending specially crafted data to execute arbitrary commands.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dap-1650