ZeroHour

CVE-2025-9769

PoC ×2niche

Command Injection in D-Link DI-7400G+ Router Management Page

CVSS 4.0
0.9 low
EPSS
26%p98
Published
()
Modified
AI analysis

CVE-2025-9769 is a command injection flaw in the sub_478D28 function of the management page /mng_platform.asp on D-Link DI-7400G+ routers. It is triggered by manipulating the 'addr' argument of that page (demonstrated with input like 'echo 12345 > poc.txt'), which lets injected commands be run on the device. Per the CVSS 4.0 vector, the attack requires physical access to the device and low privileges, and the impact on confidentiality, integrity, and availability is rated low, yielding an overall severity of 0.9 (low). Only D-Link DI-7400G+ firmware version 19.12.25A1 is identified as affected in the current data. Exploitation status: a public proof-of-concept exists (2 references), the flaw is not yet in CISA KEV, and EPSS assigns a 25.9% probability of exploitation within 30 days (98th percentile).

What to do: Check whether your DI-7400G+ runs firmware 19.12.25A1 and monitor D-Link advisories for a patched release, since no fixed version is listed in the current data. Because exploitation requires physical access, physically secure the device and restrict access to the management interface and the /mng_platform.asp 'addr' parameter to trusted users. Given the elevated EPSS score (25.9% in 30 days), prioritize verification even though the flaw is rated low severity.

Affected
D-Link DI-7400G+ Firmware19.12.25A1
Estimated exposure
nicheon the order of thousands of units at most (single small-business router model, one affected firmware version; no public install-base counts available) — No public scans or install-base statistics exist for this specific model in the data, so the estimate relies on deployment patterns: the DI-7400G+ is a niche small-business gateway with only firmware 19.12.25A1 flagged, and the physical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

Vendors
dlink
Products
di-7400g\+ firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.