Junglewise Threat Intelligence

CVE-2025-26237: D-Link DI-7001 MINI_5G command injection in msp_info

CVE-2025-26237 · Severity: high · CVSS 8.1 · Published 2026-08-24

Vendors: D-Link.

Executive brief

The D-Link DI-7001 MINI_5G is a 5G mobile gateway used to provide internet connectivity to networks. A vulnerability in the device's web management interface allows an attacker to inject arbitrary commands through the msp_info handler, potentially gaining full control of the device and all traffic passing through it.

Technical details

This vulnerability is a command injection flaw in the msp_info parameter handler of the D-Link DI-7001 MINI_5G firmware version 19.10.31A1. The vulnerable component fails to properly sanitize user input in the flag parameter, allowing an attacker to inject shell metacharacters and execute arbitrary system commands with the privileges of the web service. The attack requires network access to the device's management interface; authentication requirements are not explicitly stated but typical for such interfaces. Successful exploitation grants arbitrary command execution on the device, enabling complete system compromise, data interception, or use as an attack platform.

Affected products

  • D-Link DI-7001 MINI_5G 19.10.31A1

Timeline

  • 2026-08-24: disclosed

References