CVE-2025-57105 Details
Description
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter ac_mng_srv_host.
A command injection vulnerability has been identified in the D-Link DI-7400G+ router, specifically in the firmware version 19.12.25A1. This vulnerability allows attackers to execute arbitrary commands on the device. The issue arises in the 'jhttpd' program, within the 'mng_platform.asp' and 'wayos_ac_server.asp' files. The vulnerability can be exploited by injecting a payload into the 'ac_mng_srv_host' parameter, which is then executed by the system command without any prior filtering.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xyh4ck/iot_poc | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/xyh4ck/iot_poc | [email protected] | ExploitThird Party Advisory |
| https://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DI-7400G%2B | [email protected] | Product |
| https://www.dlink.com/en/security-bulletin/ | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dlink di-7400g+ firmware | 19.12.25a1 |
CPE
Remediation
| |
| dlink di-7400g+ | a1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | Reanalysis | [email protected] |
| Oct 1, 2025 | Initial Analysis | [email protected] |
| Aug 26, 2025 | CVE Modified | CISA-ADP |
| Aug 22, 2025 | New CVE Received | [email protected] |