CVE-2024-44402
published 2024-09-06CVE-2024-44402: D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.12%
86.3th percentile
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | di-8100g_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/msp_info.htm
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link msp_info.htm Multiple Parameters Command Injection Attempt (CVE-2025-11335, CVE-2025-6899, CVE-2024-44414, CVE-2024-44402)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/msp_info.htm|3f|"; startswith; fast_pattern; content:"flag|3d|"; distance:0; pcre:"/^(?:cmd|qos)/R"; pcre:"/(?:cmd|iface)\x3d[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/"; reference:cve,2024-44414; reference:cve,2025-11335; reference:cve,2024-44402; reference:cve,2025-6899; reference:url,www.cve.org/CVERecord/SearchResults?query=msp_info.htm; classtype:attempted-admin; sid:2065059; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_06, cve CVE_2024_44414_CVE_2025_11335_CVE_2024_44402_CVE_2025_6899, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_10_06, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
- →Exploit requests use HTTP GET method targeting /msp_info.htm with a 'flag=' parameter followed by cmd or qos parameter names containing shell metacharacters (;, newline, backtick, pipe, $) in cmd or iface parameter values — indicative of command injection.
- →Shell injection metacharacters to look for in the cmd or iface parameter values include: semicolon (;/%3B), newline (\n/%0A), backtick (`/%60), pipe (|/%7C), and dollar sign ($/%24) — both raw and URL-encoded forms should be inspected.
- →Traffic is expected in plaintext (non-TLS); deploy detection at the network perimeter and internally on traffic destined to D-Link networking equipment.
- →MITRE mapping: Initial Access (TA0001) via Exploit Public-Facing Application (T1190) — prioritize alerting on inbound exploitation attempts against D-Link DI-8100G devices.
- ·The Snort/Suricata rule (sid:2065059) covers four CVEs simultaneously (CVE-2024-44402, CVE-2024-44414, CVE-2025-11335, CVE-2025-6899); alerts will fire for any of these vulnerabilities, not exclusively CVE-2024-44402. Triage is required to attribute a specific CVE.
- ·Affected product is D-Link DI-8100G firmware version 17.12.20A1; ensure $HOME_NET in the Snort rule is scoped to include D-Link networking equipment IP ranges to reduce false positives. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS D-Link msp_info.htm Multiple Parameters Command Injection Attempt (CVE-2025-11335, CVE-2025-6899, CVE-2024-44414, CVE-2024-44402)
suricata·2025-10-06·CVSS 9.8
CVE-2024-44414 [CRITICAL] ET WEB_SPECIFIC_APPS D-Link msp_info.htm Multiple Parameters Command Injection Attempt (CVE-2025-11335, CVE-2025-6899, CVE-2024-44414, CVE-2024-44402)
ET WEB_SPECIFIC_APPS D-Link msp_info.htm Multiple Parameters Command Injection Attempt (CVE-2025-11335, CVE-2025-6899, CVE-2024-44414, CVE-2024-44402)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link msp_info.htm Multiple Parameters Command Injection Attempt (CVE-2025-11335, CVE-2025-6899, CVE-2024-44414, CVE-2024-44402)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/msp_info.htm|3f|"; startswith; fast_pattern; content:"flag|3d|"; distance:0; pcre:"/^(?:cmd|qos)/R"; pcre:"/(?:cmd|iface)\x3d[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/"; reference:cve,2024-44414; reference:cve,2025-11335; reference:cve,2024-44402; reference:cve,2025-6899; reference:url,www.cve.org/CVERecord/SearchResults?qu
No public exploits indexed.
No writeups or analysis indexed.
2024-09-06
Published