CRITICAL🇵🇱 Wersja polska

CVE-2024-23624

CVSS 9.6v3.1pub. 2024-01-26upd. 2024-11-21

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

🤖 AI Analysis
How it works

The vulnerability is located in the gena.cgi module of the D-Link DAP-1650 device firmware. An attacker reachable from the local network (AV:A vector) can send a crafted request to this module without the need to provide any authentication credentials. Inadequate input data sanitization allows injection and execution of arbitrary system commands. The commands are executed in the context of the root account, which means full administrative privileges on the device.

Impact

An attacker gains full control of the device with root privileges, which enables network configuration modification, network traffic interception, malicious software installation, and use of the device as an entry point for further attacks on the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Until an update is applied, it is recommended to isolate the device from untrusted network segments and restrict access to the management interface to trusted hosts only.

Who is affected

D-Link DAP-1650 devices — specific firmware versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Dlink Dap 1650

    HW
    Dlink
    all versions
  • Dlink Dap 1650 Firmware

    OS
    Dlink
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-40505CRITICAL9.3PL ✓same product

Path Traversal w D-Link DAP-1650 umożliwiający eskalację uprawnień

CVE-2024-23625CRITICAL9.6PL ✓same product

Command injection w D-Link DAP-1650 przez wiadomości UPnP SUBSCRIBE

CVE-2022-36588CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DAP-1650 — podatność w fileaccess.cgi

CVE-2019-12768CRITICAL9.8PL ✓same product

Pominięcie uwierzytelniania w D-Link DAP-1650 przez forceful browsing

CVE-2019-12767CRITICAL9.8PL ✓same product

Command Injection w D-Link DAP-1650 umożliwia zdalne wykonanie poleceń