CVE-2025-57105: Command Injection
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub478D28 function in in mngplatform.asp, and sub4A12DC function in wayosacserver.asp of the jhttpd program, with the parameter acmngsrvhost.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57105?
CVE-2025-57105 is considered a high-severity vulnerability due to its ability to allow remote command execution on affected devices.
How do I fix CVE-2025-57105?
To mitigate CVE-2025-57105, users should update the D-Link DI-7400G+ router firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2025-57105?
CVE-2025-57105 is a command injection vulnerability affecting the D-Link DI-7400G+ router.
Which devices are affected by CVE-2025-57105?
CVE-2025-57105 specifically affects the D-Link DI-7400G+ router.
Can CVE-2025-57105 be exploited remotely?
Yes, CVE-2025-57105 can be exploited remotely by attackers, allowing them to execute arbitrary commands on the device.