CVE-2024-7436
Published: 03 August 2024
Summary
CVE-2024-7436 is a medium-severity Command Injection (CWE-77) vulnerability in Dlink Di-8100 Firmware. Its CVSS base score is 5.3 (Medium).
Operationally, ranked in the top 17.0% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-48358
Vulnerability details
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file msp_info.htm. The manipulation of the argument cmd leads to command injection. The attack may be initiated remotely.…
more
The exploit has been disclosed to the public and may be used. The identifier VDB-273521 was assigned to this vulnerability.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.