Medium severity6.3NVD Advisory· Published Jun 30, 2025· Updated Apr 29, 2026
CVE-2025-6899
CVE-2025-6899
Description
A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The manipulation of the argument flag/cmd/iface leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
2- cpe:2.3:o:dlink:di-7300g\+_firmware:19.12.25a1:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:di-8200g_firmware:16.07.26a1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/2664521593/mycve/blob/main/D-Link_DI/CJ_IN_DLink_4_en.pdfnvdExploitIssue Tracking
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- www.dlink.comnvdProduct
News mentions
0No linked articles in our index yet.