PT-2026-7026 · D Link · Di-7100G
Jfkk
·
Published
2026-01-31
·
Updated
2026-02-09
·
CVE-2026-2193
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DI-7100G C1 version 24.04.18D1
Description
A flaw exists in the
set jhttpd info function that allows for command injection. Manipulating the usb username argument can lead to remote exploitation.Recommendations
Apply updates to address the issue in the
set jhttpd info function.
As a temporary workaround, restrict or disable the use of the usb username argument.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Di-7100G