CVE-2026-2193

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
08/02/2026
Last modified:
11/02/2026

Description

A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:di-7100g_c1_firmware:24.04.18d1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-7100g_c1:-:*:*:*:*:*:*:*