CVE-2025-3538 Details
Description
A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the component jhttpd. The manipulation of the argument callback leads to stack-based buffer overflow. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.
A stack-based buffer overflow vulnerability has been identified in the D-Link DI-8100 router, specifically in the jhttpd component's auth_asp function. This critical vulnerability, present in version 16.07.26A1, allows unauthorized attackers to manipulate the callback parameter, leading to potential denial-of-service conditions or arbitrary command execution. The vulnerability must be exploited from within the local network.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Fizz-L/CVE1/blob/main/DI-8100Command%20execution2.md | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://vuldb.com/?ctiid.304577 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.304577 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.524224 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.dlink.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink di-8100 firmware | 16.07.26a1 |
CPE
Remediation
| |
| dlink di-8100 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2025 | Initial Analysis | [email protected] |
| Apr 13, 2025 | New CVE Received | [email protected] |