VulnerabilityAnalyzed
CVE-2025-11338
This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd.
HIGH 7.4EPSS 1.00%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
- CVSS 4.0
- 7.4 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-120
- Affected
- dlink/di-7100g c1 firmware
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.327221Permissions Required, VDB Entry
- https://vuldb.com/?id.327221Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.664619Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
- https://www.yuque.com/jh0ng/vmpda6/kggo2ngrcphzvwmlPermissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.