Impact
The vulnerability is located in the firmware 19.10.31A1 of D‑Link DI‑7001 MINI_5G and allows an attacker to inject arbitrary commands through the flag parameter of the msp_info interface. If successfully exploited, the attacker could execute any shell command with the privileges of the device, compromising confidentiality, integrity, and availability of the system. This is a classic command‑injection flaw that effectively turns the device into a remote execution platform for malicious actors.
Affected Systems
D‑Link DI‑7001 MINI_5G running firmware 19.10.31A1. No other products or versions were listed as affected in the available data.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, but the high‑impact remote code execution nature gives it a severe risk posture. Although no public exploit has been documented, the likely attack vector is a local or remote network connection to the device’s management interface where the msp_info endpoint is exposed. An attacker with sufficient network access could manipulate the flag parameter to run arbitrary code, so the risk remains significant. The absence of an official patch or workaround increases the urgency for mitigation through alternative measures.
OpenCVE Enrichment