D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.
References
| Link | Resource |
|---|---|
| https://github.com/faqiadegege/IoTVuln/blob/main/DI_8400_msp_info_htm_rce/detail.md | Exploit Third Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2024-11-20 18:15
Updated : 2025-05-09 14:09
NVD link : CVE-2024-52739
Mitre link : CVE-2024-52739
CVE.ORG link : CVE-2024-52739
JSON object : View
Products Affected
dlink
- di-8400
- di-8400_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
