Severity
5.3MEDIUM
EPSS
0.4%
top 38.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by this vulnerability is the function sub_4621DC of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument hname leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages6 packages

CVEListV5d-link/di-8003g16.07.26A1, 17.12.20A1, 19.12.10A1+2
CVEListV5d-link/di-8100g16.07.26A1, 17.12.20A1, 19.12.10A1+2
CVEListV5d-link/di-8200g16.07.26A1, 17.12.20A1, 19.12.10A1+2
CVEListV5d-link/di-800316.07.26A1, 17.12.20A1, 19.12.10A1+2
CVEListV5d-link/di-810016.07.26A1, 17.12.20A1, 19.12.10A1+2

🔴Vulnerability Details

2
GHSA
GHSA-fwf7-vgqg-v7p3: A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 162025-09-15
CVEList
D-Link DI-8100/DI-8100G/DI-8200/DI-8200G/DI-8003/DI-8003G jhttpd usb_paswd.asp sub_4621DC os command injection2025-09-15

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS D-Link usb_paswd.asp hname Parameter Command Injection Attempt (CVE-2025-10440)2025-09-15