Description
A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2025-12-30: | Advisory disclosed |
| 2025-12-30: | VulDB entry created |
| 2025-12-30: | VulDB entry last update |
Credits
xuanyu (VulDB User)
References
vuldb.com/?id.338743 (VDB-338743 | D-Link DI-7400G+ msp_info.htm command injection)
vuldb.com/?ctiid.338743 (VDB-338743 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.726376 (Submit #726376 | D-Link D-Link DI_7400G+ V19.12.25A1 Command Injection)
github.com/...c/tree/main/D-Link_DI_7400G+_Command_Injection
www.dlink.com/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.