CVE-2024-23625

Publication date

2024-01-25 23:41:20

Family

XI

State

PUBLISHED

Description

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.