CVE-2024-23625

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 26, 2024
Updated: Jan 31, 2024
CWE ID 77

Summary

CVE-2024-23625 is a command injection vulnerability affecting D-Link DAP-1650 devices. The issue arises during the handling of UPnP SUBSCRIBE messages.利用上述消息处理 UPnP SUBSCRIBE 消息的漏洞, 它在 D-Link DAP-1650 设备上存在命令注入漏洞。 Bernadean McNamee, a cybersecurity researcher, discovered this vulnerability. An attacker, without authentication, can take advantage of this bug to execute commands with root privileges on the device. It is recommended that users update their devices as soon as a patch becomes available to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share