D-Link DI-7300G+
cpe:2.3:h:dlink:di-7300g+:*:*:*:*:*:*:*, +1 more
- 19.12.25A1
A critical command injection vulnerability has been identified in the D-Link DI-7300G+ router, specifically in version 19.12.25A1. The issue arises in the file httpd_debug.asp, where the Time parameter can be manipulated to inject and execute operating system commands. This vulnerability has been publicly disclosed and is actively exploitable.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device, potentially leading to full control over the router.
The vulnerability can be reproduced by sending a request to the httpd_debug.asp file with a crafted Time parameter that includes the injected command. This can be done manually or using an automated exploit, which is available on GitHub.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.