Junglewise Threat Intelligence

CVE-2025-57105: D-Link DI-7400G+ command injection in jhttpd

CVE-2025-57105 · Severity: critical · CVSS 9.8 · Published 2025-08-22

Vendors: Dlink, D-Link.

Executive brief

The D-Link DI-7400G+ router, a device used for managing enterprise-grade network traffic, contains a critical security flaw. An attacker can remotely take full control of the router by sending specially crafted requests to its management interface. This could lead to a complete network compromise, unauthorized access to internal data, or a total disruption of internet services.

Technical details

A command injection vulnerability exists in the D-Link DI-7400G+ router within the jhttpd program. The flaw is located in the sub_478D28 function in mng_platform.asp and the sub_4A12DC function in wayos_ac_server.asp. The vulnerability is triggered via the 'ac_mng_srv_host' parameter, which fails to properly neutralize special elements used in OS commands (CWE-77). An unauthenticated remote attacker can exploit this to execute arbitrary commands with the privileges of the web server. Proof-of-concept code has been identified in public repositories.

Affected products

  • D-Link DI-7400G+ 19.12.25a1

Timeline

  • 2025-08-22: disclosed: Initial NVD publication date

References