Description
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
Published: 2026-08-24
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Update
AI Analysis

Impact

The vulnerability is an unvalidated flag parameter in the msp_info interface of D‑Link DI‑8100G firmware 17.12.20A1 that allows an attacker to inject arbitrary code, effectively granting control over the device and the ability to compromise the network it is connected to. This flaw is a classic example of code execution through parameter injection and would give an attacker full administrative access, enabling persistence, data exfiltration, or use of the device as a pivot point for further attacks.

Affected Systems

Affected systems are D‑Link DI‑8100G routers running firmware version 17.12.20A1. No other vendor or product information is provided in the advisory.

Risk and Exploitability

The EPSS score is < 1%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 8.1 classifies the vulnerability as high severity. Because the flag parameter in msp_info can be manipulated remotely, the attack vector is network‑based, allowing an attacker with network access to send crafted requests to the device. The flaw enables arbitrary code execution, effectively giving the attacker full control of the router and the potential to pivot into the internal network.

Generated by OpenCVE AI on August 29, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to a version that removes the unvalidated flag parameter flaw, as provided by D‑Link.
  • If a patch is not immediately available, block or restrict access to the msp_info endpoint, for example by disabling the interface or limiting it to trusted IP addresses.
  • Segment the network so that the router is isolated from critical infrastructure, reducing the potential damage if an attacker successfully exploits the vulnerability.
  • Continuously monitor device logs for anomalous flag usage and network traffic patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on August 29, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title msp_info Flag Parameter Enables Arbitrary Code Execution on D‑Link DI‑8100G

Sat, 29 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unvalidated Flag Parameter in D-Link DI-8100G Firmware
Weaknesses CWE-20
CWE-78

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unvalidated Flag Parameter in D-Link DI-8100G Firmware
Weaknesses CWE-20
CWE-78

Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink di-8100g
Vendors & Products Dlink
Dlink di-8100g

Mon, 24 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T18:10:43.239Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-26238

cve-icon Vulnrichment

Updated: 2026-08-28T18:09:49.688Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T19:16:35.290

Modified: 2026-08-28T21:20:39.190

Link: CVE-2025-26238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T01:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')