PT-2025-40913 · D Link · Di-7100G C1
Sheratan
·
Published
2025-10-06
·
Updated
2025-11-19
·
CVE-2025-11339
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DI-7100G C1 versions up to 20250928
Description
A flaw exists in the jhttpd component of D-Link DI-7100G C1. The issue is due to a buffer overflow in the
sub 4BD4F8 function within the /webchat/hi block.asp file. The popupId argument can be manipulated to trigger this overflow, allowing for remote exploitation. The exploit has been publicly disclosed.Recommendations
Versions up to 20250928 should be updated. As a temporary workaround, consider restricting access to the
/webchat/hi block.asp file. Avoid using the popupId argument in the affected file until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Di-7100G C1