PT-2024-1619 · D Link · D-Link Dap-1650

Exodus Intelligence

·

Published

2024-01-25

·

Updated

2024-01-31

·

CVE-2024-23625

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DAP-1650 (affected versions not specified)
Description A command injection issue exists when handling UPnP SUBSCRIBE messages, allowing an unauthenticated attacker to gain command execution on the device as root. The vulnerability is related to incorrect input validation in the UPnP SUBSCRIBE Message Handler component. An attacker can exploit this issue by sending specially crafted data to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-01286
CVE-2024-23625

Affected Products

D-Link Dap-1650