Executive brief
The D-Link DI-7400G+ router, a device used for managing enterprise-grade network traffic, contains a critical security flaw. An attacker can remotely take full control of the router by sending specially crafted requests to its management interface. This could lead to a complete network compromise, unauthorized access to internal data, or a total disruption of internet services.
Technical details
A command injection vulnerability exists in the D-Link DI-7400G+ router within the jhttpd program. The flaw is located in the sub_478D28 function in mng_platform.asp and the sub_4A12DC function in wayos_ac_server.asp. The vulnerability is triggered via the 'ac_mng_srv_host' parameter, which fails to properly neutralize special elements used in OS commands (CWE-77). An unauthenticated remote attacker can exploit this to execute arbitrary commands with the privileges of the web server. Proof-of-concept code has been identified in public repositories.
Affected products
- D-Link DI-7400G+ 19.12.25a1
Timeline
- 2025-08-22: disclosed: Initial NVD publication date