A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
The vulnerability is located in the gena.cgi module of the D-Link DAP-1650 device firmware. An attacker reachable from the local network (AV:A vector) can send a crafted request to this module without the need to provide any authentication credentials. Inadequate input data sanitization allows injection and execution of arbitrary system commands. The commands are executed in the context of the root account, which means full administrative privileges on the device.
An attacker gains full control of the device with root privileges, which enables network configuration modification, network traffic interception, malicious software installation, and use of the device as an entry point for further attacks on the internal network.
Apply patches available from the manufacturer according to the references. Until an update is applied, it is recommended to isolate the device from untrusted network segments and restrict access to the management interface to trusted hosts only.
D-Link DAP-1650 devices — specific firmware versions indicated in the manufacturer's references
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDlink Dap 1650
HWDlinkall versionsDlink Dap 1650 Firmware
OSDlinkall versions
Related vulnerabilities
Path Traversal w D-Link DAP-1650 umożliwiający eskalację uprawnień
Command injection w D-Link DAP-1650 przez wiadomości UPnP SUBSCRIBE
Buffer overflow w D-Link DAP-1650 — podatność w fileaccess.cgi
Pominięcie uwierzytelniania w D-Link DAP-1650 przez forceful browsing
Command Injection w D-Link DAP-1650 umożliwia zdalne wykonanie poleceń