VYPR

DAP1650

by Dlink

CVEs (6)

  • CVE-2024-23625CriJan 26, 2024
    risk 0.64cvss 9.6epss 0.23

    A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

  • CVE-2024-23624CriJan 26, 2024
    risk 0.64cvss 9.6epss 0.26

    A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

  • CVE-2022-36588CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.02

    In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.

  • CVE-2019-12768CriDec 30, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful browsing.

  • CVE-2019-12767CriMar 21, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.

  • CVE-2024-40505CriJul 16, 2024
    risk 0.60cvss 9.3epss 0.00

    Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.