---
id: CVE-2025-11335
title: A weakness has been identified in D-Link DI-7100G C1 up to 20250928
summary: >-
  A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected
  by this vulnerability is the function sub_46409C of the file
  /msp_info.htm?flag=qos of the component jhttpd. This manipulation of the
  argument iface causes com…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
vendor: dlink
product: di-7100g_c1_firmware
affected:
  - di-7100g_c1_firmware = 2025-09-28
published: '2025-10-06'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11335'
references:
  - url: 'https://vuldb.com/?ctiid.327218'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327218'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664597'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
  - url: 'https://www.yuque.com/jh0ng/vmpda6/fpqlhpkb0orgseav'
    label: cna@vuldb.com
  - url: 'https://www.yuque.com/jh0ng/vmpda6/fpqlhpkb0orgseav#DOhrV'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.04637
epssPercentile: 0.91478
ingestedAt: '2026-10-09T12:53:28.885Z'
---

## Overview

A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of the component jhttpd. This manipulation of the argument iface causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

## Affected

- `di-7100g_c1_firmware = 2025-09-28`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
