A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://vuldb.com/?ctiid.327221 | Permissions Required VDB Entry |
| https://vuldb.com/?id.327221 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.664619 | Third Party Advisory VDB Entry |
| https://www.dlink.com/ | Product |
| https://www.yuque.com/jh0ng/vmpda6/kggo2ngrcphzvwml | Permissions Required |
Configurations
Configuration 1 (hide)
| AND |
|
History
19 Nov 2025, 21:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/?ctiid.327221 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.327221 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.664619 - Third Party Advisory, VDB Entry | |
| References | () https://www.dlink.com/ - Product | |
| References | () https://www.yuque.com/jh0ng/vmpda6/kggo2ngrcphzvwml - Permissions Required | |
| First Time |
Dlink di-7100g C1
Dlink Dlink di-7100g C1 Firmware |
|
| CPE | cpe:2.3:o:dlink:di-7100g_c1_firmware:2025-09-28:*:*:*:*:*:*:* cpe:2.3:h:dlink:di-7100g_c1:-:*:*:*:*:*:*:* |
Information
Published : 2025-10-06 16:15
Updated : 2025-11-19 21:48
NVD link : CVE-2025-11338
Mitre link : CVE-2025-11338
CVE.ORG link : CVE-2025-11338
JSON object : View
Products Affected
dlink
- di-7100g_c1
- di-7100g_c1_firmware
