Vulnerabilities
Vulnerable Software
Dlink:  >> Di-7400g+  >> a1  Security Vulnerabilities
A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used.
CVSS Score
6.3
EPSS Score
0.001
Published
2025-12-30
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter ac_mng_srv_host.
CVSS Score
9.8
EPSS Score
0.004
Published
2025-08-22


Contact Us

Shodan ® - All rights reserved