CVE-2025-4544

A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of the component jhttpd. The manipulation of the argument def_max/def_time/def_tcp_max/def_tcp_time/def_udp_max/def_udp_time/def_icmp_max leads to stack-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:di-8100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:*

History

22 May 2025, 18:24

Type Values Removed Values Added
CWE CWE-787
References () https://github.com/Yhuanhuan01/DI-8100_Vulnerability_Report/blob/main/Vulnerability_Report.md - () https://github.com/Yhuanhuan01/DI-8100_Vulnerability_Report/blob/main/Vulnerability_Report.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.308291 - () https://vuldb.com/?ctiid.308291 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.308291 - () https://vuldb.com/?id.308291 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.562695 - () https://vuldb.com/?submit.562695 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product
CPE cpe:2.3:o:dlink:di-8100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:*
First Time Dlink di-8100 Firmware
Dlink di-8100
Dlink

12 May 2025, 19:15

Type Values Removed Values Added
References () https://github.com/Yhuanhuan01/DI-8100_Vulnerability_Report/blob/main/Vulnerability_Report.md - () https://github.com/Yhuanhuan01/DI-8100_Vulnerability_Report/blob/main/Vulnerability_Report.md -

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en D-Link DI-8100 hasta la versión 16.07.26A1, clasificada como crítica. Este problema afecta a un procesamiento desconocido del archivo /ddos.asp del componente jhttpd. La manipulación del argumento def_max/def_time/def_tcp_max/def_tcp_time/def_udp_max/def_udp_time/def_icmp_max provoca un desbordamiento del búfer basado en la pila. El ataque puede ejecutarse en remoto. Es un ataque de complejidad bastante alta. Parece difícil de explotar.

11 May 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-11 19:15

Updated : 2025-05-22 18:24


NVD link : CVE-2025-4544

Mitre link : CVE-2025-4544

CVE.ORG link : CVE-2025-4544


JSON object : View

Products Affected

dlink

  • di-8100_firmware
  • di-8100
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write