CVE-2025-7762

8.8

D-Link · DI-8100

A stack-based buffer overflow vulnerability exists in the D-Link DI-8100 HTTP Request Handler, allowing remote attackers to potentially execute arbitrary code via the menu_nat_more.asp endpoint.

Executive summary

A critical stack-based buffer overflow vulnerability in the D-Link DI-8100 router allows remote attackers to compromise system integrity.

Vulnerability

This memory corruption flaw resides in the HTTP Request Handler component, specifically within the menu_nat_more.asp file. The vulnerability is triggered by remote manipulation of input, which leads to a stack-based buffer overflow, requiring low-level authenticated access to exploit.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high risk of total system compromise. A successful exploit could allow an attacker to execute arbitrary code with elevated privileges, leading to full control over the router, potential network interception, and the ability to pivot into internal segments of the corporate network.

Remediation

Immediate Action: Since no official patch is currently available, administrators should immediately restrict network access to the router management interface and isolate the device from public-facing networks.

Proactive Monitoring: Review system logs for unusual HTTP requests or repeated crashes of the web management interface, which may indicate attempted exploitation of the buffer overflow.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an intrusion detection system with custom rules to filter malicious payloads targeting the menu_nat_more.asp endpoint.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided by the vulnerability researcher.

Analyst recommendation

Due to the severity of this memory corruption vulnerability and the public availability of proof-of-concept material, immediate defensive action is required. Organizations utilizing the D-Link DI-8100 must restrict administrative access to trusted management subnets and monitor for anomalous traffic until a vendor-supplied firmware update is released.

More D-Link CVEs

Sources

Originally found and disclosed by XiDP (VulDB User), per the CVE Program record.