Description
D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.
Published: 2026-08-24
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The vulnerability is located in the firmware 19.10.31A1 of D‑Link DI‑7001 MINI_5G and allows an attacker to inject arbitrary commands through the flag parameter of the msp_info interface. If successfully exploited, the attacker could execute any shell command with the privileges of the device, compromising confidentiality, integrity, and availability of the system. This is a classic command‑injection flaw that effectively turns the device into a remote execution platform for malicious actors.

Affected Systems

D‑Link DI‑7001 MINI_5G running firmware 19.10.31A1. No other products or versions were listed as affected in the available data.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, but the high‑impact remote code execution nature gives it a severe risk posture. Although no public exploit has been documented, the likely attack vector is a local or remote network connection to the device’s management interface where the msp_info endpoint is exposed. An attacker with sufficient network access could manipulate the flag parameter to run arbitrary code, so the risk remains significant. The absence of an official patch or workaround increases the urgency for mitigation through alternative measures.

Generated by OpenCVE AI on August 28, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install any firmware updates that address the msp_info command‑injection flaw once released by D‑Link.
  • If an update is not available, limit exposure of the management interface by placing the device behind a firewall or restricting access to trusted users only.
  • Disable or remove the msp_info service if it is not required for normal operation, or block the flag parameter via web‑application firewall rules.
  • Monitor network traffic to the device for abnormal command execution patterns and consider isolating the device in a separate network segment.

Generated by OpenCVE AI on August 28, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via msp_info Flag Parameter in D‑Link DI‑7001 MINI_5G

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link di-7001 Mini
Vendors & Products D-link
D-link di-7001 Mini

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via msp_info Flag Parameter in D‑Link DI‑7001 MINI_5G
Weaknesses CWE-77

Mon, 24 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.
References

Subscriptions

D-link Di-7001 Mini
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T18:11:53.381Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-26237

cve-icon Vulnrichment

Updated: 2026-08-28T18:11:44.850Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T19:16:34.307

Modified: 2026-08-28T21:20:39.190

Link: CVE-2025-26237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:45:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')