An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication
D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgradefilter.asp file
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via mspinfo.htm.
A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgradefilterasp of the file upgradefilter.asp. The manipulation of the argument path leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.