216.73.216.226

CVE-2025-3538

· Published 13/04/2025 19:15 · Modified 13/04/2025 19:15

Labels: CVE-2025-3538 2025-04-13CVE-2025-3538CWE-119[email protected]

Essential information

Published
13/04/2025 19:15
Modified
13/04/2025 19:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the component jhttpd. The manipulation of the argument callback leads to stack-based buffer overflow. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
d-link / di-8100 cpe:2.3:a:d-link:di-8100:16.07.26A1:*:*:*:*:*:*:*

References