CVE-2025-11338

8.8

D-Link · DI-7100G C1

A buffer overflow vulnerability exists in the D-Link DI-7100G C1 login.cgi handler, which allows remote attackers to trigger memory corruption via the openid argument.

Executive summary

A critical buffer overflow vulnerability in D-Link DI-7100G C1 devices allows remote attackers to achieve unauthorized control through memory corruption.

Vulnerability

The flaw resides in the sub_4C0990 function within the /webchat/login.cgi file of the jhttpd component. By manipulating the openid argument, a remote attacker with low-level privileges can trigger a buffer overflow.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high potential for severe impact. Successful exploitation could lead to total compromise of the affected router, resulting in unauthorized network access, data exfiltration, or complete system failure. This poses a significant risk to organizational infrastructure and network security.

Remediation

Immediate Action: Since a specific patch version is currently unknown, users should immediately isolate affected devices from external network access or disable the web management interface until a security update is released by D-Link.

Proactive Monitoring: Security teams should monitor network traffic for suspicious requests targeting the /webchat/login.cgi endpoint and review authentication logs for anomalous login attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to inspect and block malformed requests containing unexpected or oversized strings within the openid parameter.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.

Analyst recommendation

Given the availability of a public proof-of-concept and the high severity of this buffer overflow, immediate action is required to secure vulnerable D-Link units. Administrators must prioritize restricting access to the affected management interface to prevent remote exploitation. Monitor the official D-Link support portal for firmware updates and apply them as soon as they become available to remediate the underlying memory corruption flaw.

More D-Link CVEs

Sources

Originally found and disclosed by sheratan (VulDB User), per the CVE Program record.