Home

Description

The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter ac_mng_srv_host.

PUBLISHED Reserved 2025-08-17 | Published 2025-08-22 | Updated 2025-08-26 | Assigner mitre

References

www.dlink.com/en/security-bulletin/

di-7400.com

www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DI-7400G%2B

github.com/xyh4ck/iot_poc

cve.org (CVE-2025-57105)

nvd.nist.gov (CVE-2025-57105)

Download JSON