Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28889 | A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited. |
Thu, 04 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink di-7400g\+ Dlink di-7400g\+ Firmware |
|
| CPEs | cpe:2.3:h:dlink:di-7400g\+:v2.a1:*:*:*:*:*:*:* cpe:2.3:o:dlink:di-7400g\+_firmware:19.12.25a1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink di-7400g\+ Dlink di-7400g\+ Firmware |
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link di-7400g+ |
|
| Vendors & Products |
D-link
D-link di-7400g+ |
Tue, 02 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited. | |
| Title | D-Link DI-7400G+ mng_platform.asp sub_478D28 command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-02T15:10:33.441Z
Reserved: 2025-08-31T17:10:22.972Z
Link: CVE-2025-9769
Updated: 2025-09-02T14:29:34.444Z
Status : Analyzed
Published: 2025-09-01T08:15:33.070
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9769
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:18Z
EUVD