CVE-2025-7602
7.2D-Link · DI-8100
A stack-based buffer overflow exists in the D-Link DI-8100 HTTP Request Handler, specifically within the /arp_sys.asp file, allowing remote manipulation of memory.
Executive summary
A critical stack-based buffer overflow vulnerability in the D-Link DI-8100 router allows remote attackers to trigger memory corruption and potentially achieve arbitrary code execution.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring within the HTTP Request Handler when processing requests to the /arp_sys.asp endpoint. Per the CVSS vector, this vulnerability requires high privileges (PR:H) to successfully execute the attack remotely.
Business impact
The vulnerability carries a CVSS score of 7.2, indicating a high severity risk. Successful exploitation could lead to a complete compromise of the affected router, resulting in unauthorized access to internal network traffic, potential man-in-the-middle attacks, or total loss of availability for the device.
Remediation
Immediate Action: Contact D-Link support or check the official vendor portal for available firmware updates addressing this memory corruption flaw. If no patch is available, restrict access to the web management interface to trusted administrative IP addresses only.
Proactive Monitoring: Review system logs for unusual HTTP request patterns targeting the /arp_sys.asp endpoint. Monitor the device for unexpected reboots or service instability, which may indicate crash attempts associated with buffer overflow exploitation.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) configured to inspect and block malformed HTTP requests directed at the management interface of the router.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Given the public disclosure of the exploit mechanism, organizations currently utilizing the D-Link DI-8100 must prioritize the hardening of the device's management interface. Until a vendor-supplied patch is confirmed and applied, restricting network access to the administrative panel is the most effective method to mitigate the risk of remote exploitation.
More D-Link CVEs
Sources
Originally found and disclosed by XiDP (VulDB User), per the CVE Program record.
- VDB-316301 | D-Link DI-8100 HTTP Request arp_sys.asp stack-based overflow Vulnerability database entry
- VDB-316301 | CTI Indicators (IOB, IOC, IOA)
- Submit #615302 | D-Link DI-8100 16.07.26A1 Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com