Impact
The vulnerability exists in the DI‑7100G C1 firmware, specifically within the set_jhttpd_info function. Manipulating the usb_username argument allows an attacker to inject arbitrary shell commands, which permits execution of unintended commands on the device. This flaw represents a classic command injection issue, reflected by CWE‑74 and CWE‑77, and could lead to unauthorized control of the device if successfully exploited.
Affected Systems
Affected vendor D‑Link, product DI‑7100G C1 running firmware version 24.04.18D1. No other firmware releases are documented as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as moderate. The EPSS score of 3% indicates a low probability of active exploitation in the near term. Although the vulnerability is not listed in the CISA KEV catalog, it is explicitly stated that remote exploitation is possible, meaning an attacker who can reach the device over the network could trigger the command injection. The impact would be execution of arbitrary commands on the device; the extent of compromise depends on the device role and the environment in which it operates.
OpenCVE Enrichment