CVE-2025-11335

Severity
5.1MEDIUM
EPSS
0.1%
top 82.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6

Description

A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of the component jhttpd. This manipulation of the argument iface causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5d-link/di-7100g_c120250928

🔴Vulnerability Details

2
CVEList
D-Link DI-7100G C1 jhttpd msp_info.htm sub_46409C command injection2025-10-06
GHSA
GHSA-f83j-cwpw-wfxw: A weakness has been identified in D-Link DI-7100G C1 up to 202509282025-10-06

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS D-Link msp_info.htm Multiple Parameters Command Injection Attempt (CVE-2025-11335, CVE-2025-6899, CVE-2024-44414, CVE-2024-44402)2025-10-06