cbcvebase.
CVE-2024-44402
published 2024-09-06

CVE-2024-44402: D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.12%
86.3th percentile
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdi-8100g_firmware

Detection & IOCsextracted from sources · hover to see the quote

url/msp_info.htm
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link msp_info.htm Multiple Parameters Command Injection Attempt (CVE-2025-11335, CVE-2025-6899, CVE-2024-44414, CVE-2024-44402)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/msp_info.htm|3f|"; startswith; fast_pattern; content:"flag|3d|"; distance:0; pcre:"/^(?:cmd|qos)/R"; pcre:"/(?:cmd|iface)\x3d[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/"; reference:cve,2024-44414; reference:cve,2025-11335; reference:cve,2024-44402; reference:cve,2025-6899; reference:url,www.cve.org/CVERecord/SearchResults?query=msp_info.htm; classtype:attempted-admin; sid:2065059; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_06, cve CVE_2024_44414_CVE_2025_11335_CVE_2024_44402_CVE_2025_6899, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_10_06, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Exploit requests use HTTP GET method targeting /msp_info.htm with a 'flag=' parameter followed by cmd or qos parameter names containing shell metacharacters (;, newline, backtick, pipe, $) in cmd or iface parameter values — indicative of command injection.
  • Shell injection metacharacters to look for in the cmd or iface parameter values include: semicolon (;/%3B), newline (\n/%0A), backtick (`/%60), pipe (|/%7C), and dollar sign ($/%24) — both raw and URL-encoded forms should be inspected.
  • Traffic is expected in plaintext (non-TLS); deploy detection at the network perimeter and internally on traffic destined to D-Link networking equipment.
  • MITRE mapping: Initial Access (TA0001) via Exploit Public-Facing Application (T1190) — prioritize alerting on inbound exploitation attempts against D-Link DI-8100G devices.
  • ·The Snort/Suricata rule (sid:2065059) covers four CVEs simultaneously (CVE-2024-44402, CVE-2024-44414, CVE-2025-11335, CVE-2025-6899); alerts will fire for any of these vulnerabilities, not exclusively CVE-2024-44402. Triage is required to attribute a specific CVE.
  • ·Affected product is D-Link DI-8100G firmware version 17.12.20A1; ensure $HOME_NET in the Snort rule is scoped to include D-Link networking equipment IP ranges to reduce false positives.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.