Impact
The vulnerability is an unvalidated flag parameter in the msp_info interface of D‑Link DI‑8100G firmware 17.12.20A1 that allows an attacker to inject arbitrary code, effectively granting control over the device and the ability to compromise the network it is connected to. This flaw is a classic example of code execution through parameter injection and would give an attacker full administrative access, enabling persistence, data exfiltration, or use of the device as a pivot point for further attacks.
Affected Systems
Affected systems are D‑Link DI‑8100G routers running firmware version 17.12.20A1. No other vendor or product information is provided in the advisory.
Risk and Exploitability
The EPSS score is < 1%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 8.1 classifies the vulnerability as high severity. Because the flag parameter in msp_info can be manipulated remotely, the attack vector is network‑based, allowing an attacker with network access to send crafted requests to the device. The flaw enables arbitrary code execution, effectively giving the attacker full control of the router and the potential to pivot into the internal network.
OpenCVE Enrichment