cbcvebase.
CVE-2025-11338
published 2025-10-06

CVE-2025-11338: A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.92%
56.1th percentile
A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdi-7100g_c1
dlinkdi-7100g_c1_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/webchat/login.cgi
path/webchat/hi_block.asp
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link hi_block.asp Multiple Parameters Buffer Overflow Attempt (CVE-2025-11338, CVE-2025-11339)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/webchat/hi_block.asp|3f|"; startswith; fast_pattern; pcre:"/(?:popupId|openid)\x3d[^&]{100,}(?:&|$)/"; reference:url,www.yuque.com/jh0ng/vmpda6/zr11zfssl8h74bn3#password%20is%20%22gstn%22; reference:cve,2025-11338; reference:cve,2025-11339; reference:url,www.yuque.com/jh0ng/vmpda6/kggo2ngrcphzvwml#password%20is%20%22orn0%22; classtype:web-application-attack; sid:2065060; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_06, cve CVE_2025_11338_CVE_2025_11339, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_10_06, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Exploit targets the 'openid' (and 'popupId') GET parameter on /webchat/hi_block.asp; look for either parameter value exceeding 100 characters in the URI, indicative of a buffer overflow attempt.
  • Attack is delivered via plain HTTP GET request to the jhttpd web component on the D-Link DI-7100G; monitor for oversized 'openid' argument in requests to /webchat/login.cgi as well.
  • The Emerging Threats rule (sid:2065060) fires on established HTTP sessions to the server with GET method and URI starting with /webchat/hi_block.asp?; deploy at perimeter and internal chokepoints.
  • Traffic is expected in plaintext (no TLS); focus inspection on unencrypted HTTP traffic to networking equipment.
  • ·The Emerging Threats rule covers both CVE-2025-11338 and CVE-2025-11339 together; tuning or whitelisting should account for both CVEs sharing the same signature (sid:2065060).
  • ·Affected firmware is D-Link DI-7100G C1 up to version 20250928; ensure version scoping is applied when deploying detections to avoid false positives on unaffected hardware.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.