PT-2025-28737 · D Link · D-Link Di-500Wf

Bluescat

·

Published

2025-07-01

·

Updated

2025-07-09

·

CVE-2025-7194

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: D-Link DI-500WF version 17.04.10A1T
Description: A critical issue affects the sprintf function of the ip position.asp file in the jhttpd component. Manipulation of the ip argument leads to a stack-based buffer overflow. This issue can be exploited remotely. An exploit has been publicly disclosed and may be utilized.
Recommendations: For D-Link DI-500WF version 17.04.10A1T, as a temporary workaround, consider restricting access to the ip position.asp file or disabling the jhttpd component until a patch is available. Avoid using the ip argument in the affected ip position.asp file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09907
CVE-2025-7194

Affected Products

D-Link Di-500Wf