Description
A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-01-08: | Advisory disclosed |
| 2026-01-08: | VulDB entry created |
| 2026-01-08: | VulDB entry last update |
Credits
Yun Zhang (VulDB User)
References
vuldb.com/?id.340129 (VDB-340129 | D-Link DI-8200G upgrade_filter.asp command injection)
vuldb.com/?ctiid.340129 (VDB-340129 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.733275 (Submit #733275 | D-Link DI_8200G Router V17.12.20A1 Command Execution)
github.com/...20A1 Command Execution Vulnerability/readme.md
github.com/...20A1 Command Execution Vulnerability/readme.md
www.dlink.com/