Security Advisory

CVE-2024-23625

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-01-25 23:41:20
Last updated 2025-05-29 15:18:31
Assigner XI
State PUBLISHED

Description

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.