CVE-2025-11407 PUBLISHED

D-Link DI-7001 MINI upgrade_filter.asp os command injection

Assigner: VulDB
Reserved: 07.10.2025 Published: 07.10.2025 Updated: 07.10.2025

A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation of the argument path causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor D-Link
Product DI-7001 MINI
Versions
  • Version 24.04.18B1 is affected

Credits

  • Yun Zhang (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE