CVE-2024-23624

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
26/01/2024
Last modified:
31/01/2024

Description

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dap-1650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dap-1650:-:*:*:*:*:*:*:*