CVE-2026-2193

HIGH WAF: High
CVSS 8.8 Published: 2026-02-08
CWE-77 CWE-77

A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
dlinkdi-7100g_c1_firmware24.04.18d1

References

Back to CVE Database