Metrics
Affected Vendors & Products
Tue, 02 Sep 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
D-link
D-link di-7400g+ |
|
Vendors & Products |
D-link
D-link di-7400g+ |
Tue, 02 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 01 Sep 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited. | |
Title | D-Link DI-7400G+ mng_platform.asp sub_478D28 command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-02T15:10:33.441Z
Reserved: 2025-08-31T17:10:22.972Z
Link: CVE-2025-9769

Updated: 2025-09-02T14:29:34.444Z

Status : Awaiting Analysis
Published: 2025-09-01T08:15:33.070
Modified: 2025-09-02T16:15:53.040
Link: CVE-2025-9769

No data.

Updated: 2025-09-02T15:23:18Z