Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-5228

Опубликовано: 27 мая 2025
Источник: nvd
CVSS3: 8.8
CVSS2: 8.3
EPSS Низкий

Описание

A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi of the component jhttpd. The manipulation of the argument notify leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dlink:di-8100_firmware:*:*:*:*:*:*:*:*
Версия до 20250523 (включая)
cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00237
Низкий

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.8
github
9 месяцев назад

A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi of the component jhttpd. The manipulation of the argument notify leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
fstec
9 месяцев назад

Уязвимость функции httpd_get_parm() компонента jhttpd микропрограммного обеспечения маршрутизаторов D-Link DI-8100, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 47%
0.00237
Низкий

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-119