Dlink Di-7001Mini-8G Firmware vulnerabilities

3 known vulnerabilities affecting dlink/di-7001mini-8g_firmware.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-12313MEDIUMCVSS 5.3v19.09.19a1v24.04.18b12025-10-27
CVE-2025-12313 [MEDIUM] CWE-74 CVE-2025-12313: A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function of the file /msp_info.htm. Such manipulation of the argument cmd leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-11408HIGHCVSS 7.4v24.04.18b12025-10-07
CVE-2025-11408 [HIGH] CWE-119 CVE-2025-11408: A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element i A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown function of the file /dbsrv.asp. Such manipulation of the argument str leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-11407MEDIUMCVSS 5.3v24.04.18b12025-10-07
CVE-2025-11407 [MEDIUM] CWE-77 CVE-2025-11407: A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation of the argument path causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
nvd