8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Basic Information
ID
CVE-2025-11338
Source
VulDB
Published
Oct 6, 2025 at 16:02
Modified
Oct 6, 2025 at 17:16
Affected Product
Vendor
D-Link
Product
DI-7100G C1
Version
20250928
Affected Versions
D-Link DI-7100G C1 20250928