PT-2026-80994 · D Link · Di-8100

CVE-2025-26238

·

Published

2026-08-24

·

Updated

2026-08-28

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions D-Link DI-8100G version 17.12.20A1
Description An issue exists in the msp info endpoint where the flag parameter can be exploited to execute arbitrary code. Arbitrary code execution allows an attacker to run unauthorized commands on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26238

Affected Products

Di-8100