CVE-2025-11339
8.8D-Link · DI-7100G C1
A buffer overflow vulnerability in the D-Link DI-7100G C1 allows remote attackers to trigger memory corruption via the popupId argument in the hi_block.asp file.
Executive summary
A remote buffer overflow vulnerability in D-Link DI-7100G C1 routers poses a significant risk of arbitrary code execution or system instability.
Vulnerability
This is a buffer overflow (CWE-120) occurring within the sub_4BD4F8 function of the jhttpd component. The vulnerability is triggered by sending a malicious input to the popupId argument within the /webchat/hi_block.asp file, which can be exploited by an authenticated user remotely.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity risk that could lead to full system compromise. Successful exploitation allows an attacker to gain control over the networking device, potentially facilitating lateral movement within the network, interception of traffic, or complete service disruption. The loss of integrity and availability for critical infrastructure components such as routers can result in significant operational downtime and potential data exposure.
Remediation
Immediate Action: Since a specific patch is currently unknown, administrators should restrict network access to the management interface of the affected devices and ensure the device is not reachable from the public internet.
Proactive Monitoring: Monitor system logs for unusual crashes or restarts of the jhttpd process and look for unexpected HTTP requests targeting the /webchat/hi_block.asp endpoint.
Compensating Controls: Implement strict firewall rules to limit access to the router management interface to trusted administrative IP addresses only.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the referenced security researcher write-up.
Analyst recommendation
Given the high CVSS score and the public availability of exploit details, this vulnerability should be treated with urgency. Administrators must prioritize isolating the affected D-Link devices from untrusted network segments until the vendor provides a firmware update. Continuous monitoring of device logs is essential to detect any early signs of exploitation attempts.
More D-Link CVEs
Sources
Originally found and disclosed by sheratan (VulDB User), per the CVE Program record.
- VDB-327222 | D-Link DI-7100G C1 jhttpd hi_block.asp sub_4BD4F8 buffer overflow Vulnerability database entry
- VDB-327222 | CTI Indicators (IOB, IOC, IOA)
- Submit #664635 | D-Link DI-7100G C1 Buffer Overflow Third-party advisory
- Related
- Exploit / PoC
- dlink.com