← Back to browse · API

CVE-2024-23624

Severity
CRITICAL
CVSS
9.6
EPSS
0.25988
Risk score
47.5
CISA KEV
No
PoC
No
Published
2024-01-25
Modified
2025-06-17
First seen
2026-08-07
Aliases
EUVD-2024-21118, GHSA-G338-CR75-98GG
Products
D-Link:DAP-1650, D-Link:DAP-1650 0 ≤1.04B01
Sources
euvd EUVD-2024-21118

Description

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

References