CRITICAL🇵🇱 Wersja polska

CVE-2024-23625

CVSS 9.6v3.1pub. 2024-01-26upd. 2024-11-21

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

🤖 AI Analysis
How it works

The vulnerability consists of improper handling of input data contained in UPnP SUBSCRIBE messages — this data is passed to system command execution without proper validation or sanitization. An attacker operating on the same local network can send a specially crafted UPnP SUBSCRIBE message, injecting malicious system commands into it. Since the exploit does not require authentication, network access to the vulnerable device is sufficient.

Impact

An attacker gains remote code execution (RCE) on the device with root privileges, which means complete takeover of control — ability to modify configuration, install backdoors, intercept network traffic, and use the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Until the fix is implemented, it is recommended to block access to the UPnP service from the local network for untrusted devices, or disable the UPnP function on the device if not required.

Who is affected

D-Link DAP-1650 — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Dlink Dap 1650

    HW
    Dlink
    all versions
  • Dlink Dap 1650 Firmware

    OS
    Dlink
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-40505CRITICAL9.3PL ✓same product

Path Traversal w D-Link DAP-1650 umożliwiający eskalację uprawnień

CVE-2024-23624CRITICAL9.6PL ✓same product

Command injection w D-Link DAP-1650 — nieuwierzytelniony dostęp root

CVE-2022-36588CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DAP-1650 — podatność w fileaccess.cgi

CVE-2019-12768CRITICAL9.8PL ✓same product

Pominięcie uwierzytelniania w D-Link DAP-1650 przez forceful browsing

CVE-2019-12767CRITICAL9.8PL ✓same product

Command Injection w D-Link DAP-1650 umożliwia zdalne wykonanie poleceń