Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink di-7001mini-8g Dlink di-7001mini-8g Firmware |
|
| CPEs | cpe:2.3:h:dlink:di-7001mini-8g:b1:*:*:*:*:*:*:* cpe:2.3:o:dlink:di-7001mini-8g_firmware:24.04.18b1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink di-7001mini-8g Dlink di-7001mini-8g Firmware |
Wed, 08 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link di-7001 Mini |
|
| Vendors & Products |
D-link
D-link di-7001 Mini |
Tue, 07 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation of the argument path causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Title | D-Link DI-7001 MINI upgrade_filter.asp os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-10-07T20:33:12.045Z
Reserved: 2025-10-07T07:23:37.593Z
Link: CVE-2025-11407
Updated: 2025-10-07T20:33:07.798Z
Status : Analyzed
Published: 2025-10-07T20:15:33.400
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-11407
No data.
OpenCVE Enrichment
Updated: 2025-10-08T13:35:27Z