CVE-2025-57105CRITICAL 9.8EPSS p88.3%

CVE-2025-57105CVE-2025-57105

Description

The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter ac_mng_srv_host.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.71% probability of exploitation · percentile 88.3% · 2026-06-18T12:00:27Z
Published2025-08-22
Last modified2025-10-02

Underlying weaknesses· 1

CWE-77

References

  1. http://di-7400.com
  2. https://github.com/xyh4ck/iot_poc
  3. https://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DI-7400G%2B
  4. https://www.dlink.com/en/security-bulletin/
  5. https://github.com/xyh4ck/iot_poc

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in a Command ('Command Injection')cwe-770%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-15357
CVE
CVE-2025-5492
CVE
CVE-2025-4340
CVE
CVE-2025-11407
CVE
CVE-2025-44880
CVE
CVE-2025-6896
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.