CVE-2024-51151
PoC moderateUnauthenticated Command Injection RCE in D-Link DI-8200 VPN Gateway
CVE-2024-51151 is an unauthenticated command injection flaw (CWE-77/CWE-78) in the msp_info_htm function of the D-Link DI-8200 VPN gateway, with firmware version 16.07.26A1 cited as vulnerable. A remote attacker sends crafted HTTP requests to the device's web management interface, injecting arbitrary operating system commands via the flag and cmd parameters, which the handler passes to the system without sanitization. Successful exploitation yields remote command execution with the privileges of the web service, enabling full takeover of the gateway, theft of configuration, and use of the device as a pivot point into the protected network. Any DI-8200 gateway whose management interface is reachable by an attacker (for example, exposed on the WAN side) is affected; the source data lists only 16.07.26A1 and does not enumerate other affected version ranges. No in-the-wild exploitation is confirmed and the flaw is not in CISA KEV, but a public proof of concept exists and the 30.4% EPSS score (98th percentile) signals an elevated likelihood of exploitation within 30 days.
What to do: Restrict access to the DI-8200 web management interface (limit to trusted management IPs or via VPN, disable WAN-side remote administration) and review HTTP logs for requests to msp_info_htm containing suspicious flag/cmd parameter values. Check D-Link's support and advisory pages for updated DI-8200 firmware, as the source data does not specify a fixed version. Given the available public PoC and high EPSS, prioritize remediation for any gateway exposed to the internet.
| D-Link DI-8200 firmware | 16.07.26A1 (the version cited as vulnerable; affected ranges are not enumerated in the source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.
- Vendors
- dlink
- Products
- di-8200 firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.