cbcvebase.

Dlink Di-7001Mini-8G Firmware vulnerabilities

4 known vulnerabilities affecting dlink/di-7001mini-8g_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1

Vulnerabilities

Page 1 of 1
CVE-2025-11407P2CRITICALCVSS 9.8v24.04.18b12025-10-07
CVE-2025-11407 [CRITICAL] CWE-77 CVE-2025-11407: A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation of the argument path causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
nvd
CVE-2025-12313P2CRITICALCVSS 9.8v19.09.19a1v24.04.18b12025-10-27
CVE-2025-12313 [CRITICAL] CWE-74 CVE-2025-12313: A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function of the file /msp_info.htm. Such manipulation of the argument cmd leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-11408P2CRITICALCVSS 9.8v24.04.18b12025-10-07
CVE-2025-11408 [CRITICAL] CWE-119 CVE-2025-11408: A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element i A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown function of the file /dbsrv.asp. Such manipulation of the argument str leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-10270P3HIGHCVSS 7.5v19.09.19a12026-06-01
CVE-2026-10270 [HIGH] CWE-119 CVE-2026-10270: A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprin A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
nvd
Dlink Di-7001Mini-8G Firmware vulnerabilities | cvebase