9.8
CVSSv3

CVE-2024-23625

Published: 26/01/2024 Updated: 31/01/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9

Vulnerability Summary

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dap-1650_firmware -