CVE-2025-7911: D-Link DI-8100 jhttpd upnp_ctrl.asp sprintf stack-based overflow
A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnpctrl.asp of the component jhttpd. The manipulation of the argument removeextproto/removeextport leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7911?
CVE-2025-7911 is classified as a critical vulnerability.
How do I fix CVE-2025-7911?
To fix CVE-2025-7911, apply the latest firmware updates from D-Link for the DI-8100 device.
What component is affected by CVE-2025-7911?
CVE-2025-7911 affects the jhttpd component, specifically the sprintf function in the /upnp_ctrl.asp file.
What type of vulnerability is CVE-2025-7911?
CVE-2025-7911 is a stack-based buffer overflow vulnerability.
What impact does CVE-2025-7911 have on systems?
CVE-2025-7911 can lead to potential remote code execution due to the stack-based buffer overflow.