---
id: CVE-2025-11338
title: A flaw has been found in D-Link DI-7100G C1 up to 20250928
summary: >-
  A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability
  affects the function sub_4C0990 of the file /webchat/login.cgi of the
  component jhttpd. Executing manipulation of the argument openid can lead to
  buffer overf…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: dlink
product: di-7100g_c1_firmware
affected:
  - di-7100g_c1_firmware = 2025-09-28
published: '2025-10-06'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11338'
references:
  - url: 'https://vuldb.com/?ctiid.327221'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327221'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664619'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
  - url: 'https://www.yuque.com/jh0ng/vmpda6/kggo2ngrcphzvwml'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00997
epssPercentile: 0.61575
ingestedAt: '2026-10-09T12:53:28.907Z'
---

## Overview

A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

## Affected

- `di-7100g_c1_firmware = 2025-09-28`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
