CVE-2026-2193: D-Link Di-7100g c1 Firmware

High severity, CVSS 8.8. EPSS: 4% chance of exploitation in the next 30 days.

A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible.

Affected products

  • D-Link Di-7100g c1 Firmware: version 24.04.18d1 only

Published 2026-02-08. Last modified 2026-06-17.