CVE-2025-8175: D-Link DI-8400 jhttpd usb_paswd.asp null pointer dereference
A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usbpaswd.asp of the component jhttpd. The manipulation of the argument shareenable leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8175?
CVE-2025-8175 is classified as problematic due to its potential to cause a null pointer dereference.
How do I fix CVE-2025-8175?
To mitigate CVE-2025-8175, users should disable the 'share_enable' option in the configuration settings.
What component is affected by CVE-2025-8175?
CVE-2025-8175 affects the usb_paswd.asp file in the jhttpd component of the D-Link DI-8400.
What is the potential impact of CVE-2025-8175?
The exploitation of CVE-2025-8175 can lead to application crashes or denial of service due to null pointer dereference.
Which devices are vulnerable to CVE-2025-8175?
Devices running the D-Link DI-8400 with software version 16.07.26A1 are vulnerable to CVE-2025-8175.