← Back to browse · API

CVE-2024-23625

Severity
CRITICAL
CVSS
9.6
EPSS
0.22836
Risk score
46.39
CISA KEV
No
PoC
No
Published
2024-01-25
Modified
2025-05-29
First seen
2026-08-07
Aliases
EUVD-2024-21119, GHSA-GQC3-HMP6-WX23
Products
D-Link:DAP-1650, D-Link:DAP-1650 0 ≤1.04B01
Sources
euvd EUVD-2024-21119

Description

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

References