216.73.216.233

CVE-2025-7911

· Published 20/07/2025 23:15 · Modified 21/07/2025 13:15

Labels: CVE-2025-7911 2025-07-20CVE-2025-7911CWE-119[email protected]

Essential information

Published
20/07/2025 23:15
Modified
21/07/2025 13:15
Author
Creator
CVSS
7.4 HIGH (v3) 7.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhttpd. The manipulation of the argument remove_ext_proto/remove_ext_port leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
d-link / di-8100 cpe:2.3:a:d-link:di-8100:1.0:*:*:*:*:*:*:*

References