Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hhc-2692-pw9v

Опубликовано: 29 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 0.9
CVSS3: 6.2

Описание

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input echo 12345 > poc.txt results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input echo 12345 > poc.txt results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

EPSS

Процентиль: 98%
0.25875
Средний

0.9 Low

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-74
CWE-77

Связанные уязвимости

CVSS3: 4.1
nvd
12 месяцев назад

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

CVSS3: 4.1
fstec
12 месяцев назад

Уязвимость функции sub_478D28 микропрограммного обеспечения маршрутизатора D-Link DI-7400G+, позволяющая нарушителю получить несанкционированный доступ к интерфейсу администратора

EPSS

Процентиль: 98%
0.25875
Средний

0.9 Low

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-74
CWE-77