CVE-2025-11338: D-Link DI-7100G C1 jhttpd login.cgi sub_4C0990 buffer overflow
A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11338?
CVE-2025-11338 is identified as a high-severity vulnerability due to the potential for remote code execution through buffer overflow.
How do I fix CVE-2025-11338?
To fix CVE-2025-11338, update the D-Link DI-7100G C1 and D-Link jhttpd to a version beyond 20250928.
What systems are affected by CVE-2025-11338?
CVE-2025-11338 affects the D-Link DI-7100G C1 and the D-Link jhttpd software versions up to 20250928.
What kind of attack can be executed using CVE-2025-11338?
CVE-2025-11338 allows for a remote attack through manipulation of the openid argument leading to a buffer overflow.
Who is responsible for addressing CVE-2025-11338?
The responsibility for addressing CVE-2025-11338 lies with the users of affected D-Link products to apply necessary security updates.