CVE-2024-7436: D-Link DI-8100 msp_info.htm msp_info_htm command injection
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function mspinfohtm of the file mspinfo.htm. The manipulation of the argument cmd leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273521 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7436?
CVE-2024-7436 is classified as a critical vulnerability.
How does CVE-2024-7436 affect D-Link DI-8100 firmware?
CVE-2024-7436 affects the msp_info_htm function within the D-Link DI-8100 firmware version 16.07.
What type of attack can be executed using CVE-2024-7436?
CVE-2024-7436 allows for remote command injection through manipulation of the cmd argument.
Is there a specific version of D-Link firmware that is vulnerable to CVE-2024-7436?
Yes, D-Link DI-8100 firmware version 16.07 is specifically vulnerable to CVE-2024-7436.
What should be done to mitigate the risks associated with CVE-2024-7436?
To mitigate CVE-2024-7436, users should upgrade to a patched version of the firmware recommended by D-Link.