PT-2025-47045 · D Link · Dir-816

Lexpl0It

·

Published

2025-10-30

·

Updated

2025-11-20

·

CVE-2025-13190

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-816L version 2 06 b09 beta
Description A stack-based buffer overflow exists in the scandir main function of the /portal/ ajax exporer.sgi file. This flaw can be exploited remotely. The argument en can be manipulated to trigger the overflow. The exploit is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-14393
CVE-2025-13190

Affected Products

Dir-816