CVE-2025-7603
7.2D-Link · DI-8100
A stack-based buffer overflow in the D-Link DI-8100 HTTP request handler allows remote attackers to trigger memory corruption via the /jingx.asp endpoint.
Executive summary
A critical stack-based buffer overflow vulnerability in the D-Link DI-8100 router allows remote attackers to achieve unauthorized memory corruption.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) occurring within the /jingx.asp file of the HTTP request handler. Based on the CVSS vector (PR:H), this attack requires an authenticated administrator to trigger the flaw remotely.
Business impact
The vulnerability carries a CVSS score of 7.2, indicating a high severity risk. Successful exploitation could lead to system instability, denial of service, or potential arbitrary code execution, which may result in full compromise of the network gateway and exposure of internal traffic.
Remediation
Immediate Action: As no patch is currently available, administrators should restrict network access to the management interface of the affected device to trusted IP addresses only.
Proactive Monitoring: Monitor system logs for repeated access attempts to the /jingx.asp endpoint or unusual device reboots that may indicate crash-based exploitation attempts.
Compensating Controls: Implement strict firewall rules to ensure the device management interface is not exposed to the public internet or untrusted network segments.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists in the technical write-up provided by the researcher (referenced at GitHub).
Analyst recommendation
Given the availability of a public proof-of-concept, the risk of exploitation is elevated. Organizations currently utilizing the D-Link DI-8100 must immediately isolate management interfaces from external access and monitor for vendor updates, as the vulnerability provides a direct pathway to device compromise.
More D-Link CVEs
Sources
Originally found and disclosed by XiDP (VulDB User), per the CVE Program record.
- VDB-316302 | D-Link DI-8100 HTTP Request jingx.asp stack-based overflow Vulnerability database entry
- VDB-316302 | CTI Indicators (IOB, IOC, IOA)
- Submit #615320 | D-Link DI-8100 16.07.26A1 Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com