CVE-2025-6899
MEDIUMD-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1 - OS Command Injection via msp_info.htm flag/cmd/iface Parameter
Title source: llmDescription
A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The manipulation of the argument flag/cmd/iface leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.314391
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.314391
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.604444
Exploit, Issue Tracking exploit
https://github.com/2664521593/mycve/blob/main/D-Link_DI/CJ_IN_DLink_4_en.pdf
Product product
https://www.dlink.com/
Scores
CVSS v3
6.3
EPSS
0.0214
EPSS Percentile
84.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-77
CWE-78
Status
published
Products (2)
dlink/di-7300g\+_firmware
19.12.25a1
dlink/di-8200g_firmware
16.07.26a1
Published
Jun 30, 2025
Tracked Since
Feb 18, 2026