Description
A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the component jhttpd. The manipulation of the argument popupId leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Published: 2025-10-06
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-32557 A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the component jhttpd. The manipulation of the argument popupId leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Wed, 19 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink di-7100g C1
Dlink di-7100g C1 Firmware
CPEs cpe:2.3:h:dlink:di-7100g:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-7100g_firmware:2025-09-28c1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-7100g_c1:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-7100g_c1_firmware:2025-09-28:*:*:*:*:*:*:*
Vendors & Products Dlink di-7100g
Dlink di-7100g Firmware
Dlink di-7100g C1
Dlink di-7100g C1 Firmware

Wed, 19 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink di-7100g
Dlink di-7100g Firmware
CPEs cpe:2.3:h:dlink:di-7100g:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-7100g_firmware:2025-09-28c1:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink di-7100g
Dlink di-7100g Firmware

Wed, 08 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link di-7100g C1
Vendors & Products D-link
D-link di-7100g C1

Mon, 06 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the component jhttpd. The manipulation of the argument popupId leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Title D-Link DI-7100G C1 jhttpd hi_block.asp sub_4BD4F8 buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Di-7100g C1
Dlink Di-7100g C1 Di-7100g C1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-10-06T17:16:06.762Z

Reserved: 2025-10-05T22:09:06.624Z

Link: CVE-2025-11339

cve-icon Vulnrichment

Updated: 2025-10-06T17:00:44.483Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-06T17:16:04.683

Modified: 2025-11-19T21:47:37.660

Link: CVE-2025-11339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-08T13:39:14Z

Weaknesses