Junglewise Threat Intelligence

CVE-2025-26238: D-Link DI-8100G command injection in msp_info

CVE-2025-26238 · Severity: high · CVSS 8.1 · Published 2026-08-24

Vendors: D-Link.

Executive brief

The D-Link DI-8100G is a network appliance used in enterprise environments for network access and management. A command injection vulnerability in the msp_info parameter allows an unauthenticated attacker to execute arbitrary code on the device, potentially compromising network security, enabling lateral movement, and allowing theft or manipulation of critical network data.

Technical details

This vulnerability is a command injection flaw in the msp_info endpoint of the jhttpd web server component running on D-Link DI-8100G firmware version 17.12.20A1. The flag parameter is not properly sanitized, allowing attackers to inject arbitrary shell commands that are executed with the privileges of the web server process. The attack vector is network-based and requires no authentication. Successful exploitation grants an attacker code execution capabilities on the affected device. A patch status is not mentioned in the available advisory information.

Affected products

  • D-Link DI-8100G 17.12.20A1

Timeline

  • 2026-08-24: disclosed

References