CRITICAL🇵🇱 Wersja polska

CVE-2024-40505

CVSS 9.3v3.1pub. 2024-07-16upd. 2025-05-29

Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.

🤖 AI Analysis
How it works

The vulnerability exists in the hedwig.cgi component of the D-Link DAP-1650 device. An attacker with local access to the device can exploit improper file path handling (CWE-35 — path traversal) to escape the allowed directory and gain access to system resources outside the intended scope. As a result, privilege escalation to a higher privilege level is possible.

Impact

An attacker can gain elevated privileges on the device, which consequently may lead to complete takeover of the router, including configuration modification, network traffic interception, or further lateral movement in the network.

Mitigation & patch

Security patches available from the manufacturer should be applied in accordance with the references (D-Link security announcement SAP10266 available at supportannouncement.us.dlink.com). It is recommended to update the device firmware to a vulnerability-free version as soon as possible.

Who is affected

D-Link DAP-1650 with firmware version 1.03

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Dlink Dap 1650

    HW
    Dlink
    all versions
  • Dlink Dap 1650 Firmware

    OS
    Dlink
    1.03
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path TraversalLPE
CWE
References

Related vulnerabilities

CVE-2024-23624CRITICAL9.6PL ✓same product

Command injection w D-Link DAP-1650 — nieuwierzytelniony dostęp root

CVE-2024-23625CRITICAL9.6PL ✓same product

Command injection w D-Link DAP-1650 przez wiadomości UPnP SUBSCRIBE

CVE-2022-36588CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DAP-1650 — podatność w fileaccess.cgi

CVE-2019-12768CRITICAL9.8PL ✓same product

Pominięcie uwierzytelniania w D-Link DAP-1650 przez forceful browsing

CVE-2019-12767CRITICAL9.8PL ✓same product

Command Injection w D-Link DAP-1650 umożliwia zdalne wykonanie poleceń