Executive brief
The D-Link DI-8100G is a network appliance used in enterprise environments for network access and management. A command injection vulnerability in the msp_info parameter allows an unauthenticated attacker to execute arbitrary code on the device, potentially compromising network security, enabling lateral movement, and allowing theft or manipulation of critical network data.
Technical details
This vulnerability is a command injection flaw in the msp_info endpoint of the jhttpd web server component running on D-Link DI-8100G firmware version 17.12.20A1. The flag parameter is not properly sanitized, allowing attackers to inject arbitrary shell commands that are executed with the privileges of the web server process. The attack vector is network-based and requires no authentication. Successful exploitation grants an attacker code execution capabilities on the affected device. A patch status is not mentioned in the available advisory information.
Affected products
- D-Link DI-8100G 17.12.20A1
Timeline
- 2026-08-24: disclosed