CVE-2025-6899: D-Link Di-7300g+ Firmware

High severity, CVSS 8.8. EPSS: 4.7% chance of exploitation in the next 30 days.

A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The manipulation of the argument flag/cmd/iface leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • D-Link Di-7300g+ Firmware: version 19.12.25a1 only
  • D-Link Di-8200g Firmware: version 16.07.26a1 only

Published 2025-06-30. Last modified 2026-06-17.