Description
A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible.
Published: 2026-02-08
Score: 5.3 Medium
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the DI‑7100G C1 firmware, specifically within the set_jhttpd_info function. Manipulating the usb_username argument allows an attacker to inject arbitrary shell commands, which permits execution of unintended commands on the device. This flaw represents a classic command injection issue, reflected by CWE‑74 and CWE‑77, and could lead to unauthorized control of the device if successfully exploited.

Affected Systems

Affected vendor D‑Link, product DI‑7100G C1 running firmware version 24.04.18D1. No other firmware releases are documented as vulnerable.

Risk and Exploitability

The CVSS score of 5.3 classifies the vulnerability as moderate. The EPSS score of 3% indicates a low probability of active exploitation in the near term. Although the vulnerability is not listed in the CISA KEV catalog, it is explicitly stated that remote exploitation is possible, meaning an attacker who can reach the device over the network could trigger the command injection. The impact would be execution of arbitrary commands on the device; the extent of compromise depends on the device role and the environment in which it operates.

Generated by OpenCVE AI on June 18, 2026 at 13:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire the latest firmware from D‑Link that contains the fix for the set_jhttpd_info command injection and install it.
  • Restrict access to the device’s management interface by allowing only trusted IP ranges or internal networks, using firewall or ACL rules.
  • If the web or management interface is not needed for normal operation, disable it or confine it to a secure network segment.

Generated by OpenCVE AI on June 18, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 11 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink di-7100g C1
Dlink di-7100g C1 Firmware
CPEs cpe:2.3:h:dlink:di-7100g_c1:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-7100g_c1_firmware:24.04.18d1:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink di-7100g C1
Dlink di-7100g C1 Firmware

Mon, 09 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link di-7100g C1
Vendors & Products D-link
D-link di-7100g C1

Sun, 08 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible.
Title D-Link DI-7100G C1 set_jhttpd_info command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

D-link Di-7100g C1
Dlink Di-7100g C1 Di-7100g C1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:51:21.510Z

Reserved: 2026-02-07T17:32:45.833Z

Link: CVE-2026-2193

cve-icon Vulnrichment

Updated: 2026-02-09T16:43:01.080Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-08T23:15:49.840

Modified: 2026-06-17T10:30:30.867

Link: CVE-2026-2193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T13:45:05Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')