A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
The vulnerability consists of improper handling of input data contained in UPnP SUBSCRIBE messages — this data is passed to system command execution without proper validation or sanitization. An attacker operating on the same local network can send a specially crafted UPnP SUBSCRIBE message, injecting malicious system commands into it. Since the exploit does not require authentication, network access to the vulnerable device is sufficient.
An attacker gains remote code execution (RCE) on the device with root privileges, which means complete takeover of control — ability to modify configuration, install backdoors, intercept network traffic, and use the device as an entry point to the internal network.
Apply patches available from the manufacturer according to the references. Until the fix is implemented, it is recommended to block access to the UPnP service from the local network for untrusted devices, or disable the UPnP function on the device if not required.
D-Link DAP-1650 — versions indicated in the manufacturer's references
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDlink Dap 1650
HWDlinkall versionsDlink Dap 1650 Firmware
OSDlinkall versions
Related vulnerabilities
Path Traversal w D-Link DAP-1650 umożliwiający eskalację uprawnień
Command injection w D-Link DAP-1650 — nieuwierzytelniony dostęp root
Buffer overflow w D-Link DAP-1650 — podatność w fileaccess.cgi
Pominięcie uwierzytelniania w D-Link DAP-1650 przez forceful browsing
Command Injection w D-Link DAP-1650 umożliwia zdalne wykonanie poleceń