CVE-2024-23624: D-Link Dap-1650 Firmware

Critical severity, CVSS 9.8. EPSS: 26% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

Affected products

  • D-Link Dap-1650 Firmware: affected versions not specified

Published 2024-01-26. Last modified 2026-06-17.