CVE-2025-5492 | D-Link DI-500WF-WT up to 20250511 jhttpd /msp_info.htm?flag=cmd sub_456DE8 command injection (EUVD-2025-16723)
A vulnerability labeled as critical has been found in D-Link DI-500WF-WT up to 20250511. This issue affects the function sub_456DE8 of the file /msp_info.htm?flag=cmd of the component jhttpd. The manipulation of the argument cmd results in command injection.
This vulnerability was named CVE-2025-5492. The attack may be performed from a remote location. In addition, an exploit is available.