First published: Sun May 11 2025(Updated: )
A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of the component jhttpd. The manipulation of the argument def_max/def_time/def_tcp_max/def_tcp_time/def_udp_max/def_udp_time/def_icmp_max leads to stack-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DI-8100 | <=16.07.26A1 | |
D-Link jhttpd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4544 is classified as a critical vulnerability.
CVE-2025-4544 affects the D-Link DI-8100 router and the jhttpd component.
To resolve CVE-2025-4544, upgrade the D-Link DI-8100 to a version later than 16.07.26A1.
CVE-2025-4544 involves an unknown processing issue related to the file /ddos.asp.
CVE-2025-4544 entails the manipulation of several arguments including def_max, def_time, def_tcp_max, def_tcp_time, def_udp_max, and def_udp_time.