VYPR
Unrated severityNVD Advisory· Published Jun 3, 2025· Updated Jun 3, 2025

D-Link DI-500WF-WT /usr/sbin/jhttpd msp_info.htm sub_456DE8 command injection

CVE-2025-5492

Description

A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnerability is the function sub_456DE8 of the file /msp_info.htm?flag=cmd of the component /usr/sbin/jhttpd. The manipulation of the argument cmd leads to command injection. The attack can be launched remotely.

Affected products

2
  • Dlink/DI-500WFllm-fuzzy
    Range: <=20250511
  • D-Link/DI-500WF-WTv5
    Range: 20250511

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.