CVE 2.4 LOW

D-Link DI-7400G+ mng_platform.asp sub_478D28 command injection_CVE-2025-9769

2.4 / 10
LOW
CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

Basic Information

ID CVE-2025-9769
Source VulDB
Published Sep 1, 2025 at 08:02

Affected Product

Vendor D-Link
Product DI-7400G+
Version 19.12.25A1
Affected Versions D-Link DI-7400G+ 19.12.25A1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.