CVE-2025-26238: Code Injection
Published Aug 24, 2026
·Updated
In D-Link DI-8100G 17.12.20A1, the flag parameter in mspinfo can be exploited to execute arbitrary code.
Affected Software
1 affected component
D-Link DI-8100G=17.12.20A1
Event History
Aug 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which product version is identified as affected?
The reported affected version is D-Link DI-8100G 17.12.20A1.
2
What is required to exploit this issue?
An attacker must be able to supply a crafted flag parameter to msp_info. The provided data does not state whether authentication or network access is required.
3
What is the impact of successful exploitation?
Successful exploitation can result in arbitrary code execution.