CVE-2014-3872: D-Link Dap-1350

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.

Affected products

  • D-Link Dap-1350
  • D-Link Dap-1350 Firmware: up to and including 1.14; version 1.10 only

Published 2014-05-27. Last modified 2026-06-17.