---
id: CVE-2025-11339
title: A vulnerability has been found in D-Link DI-7100G C1 up to 20250928
summary: >-
  A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This
  issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the
  component jhttpd. The manipulation of the argument popupId leads to buffer
  overflow.…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: dlink
product: di-7100g_c1_firmware
affected:
  - di-7100g_c1_firmware = 2025-09-28
published: '2025-10-06'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11339'
references:
  - url: 'https://vuldb.com/?ctiid.327222'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327222'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664635'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
  - url: 'https://www.yuque.com/jh0ng/vmpda6/zr11zfssl8h74bn3'
    label: cna@vuldb.com
  - url: 'https://www.yuque.com/jh0ng/vmpda6/zr11zfssl8h74bn3#Wjajr'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00956
epssPercentile: 0.60254
ingestedAt: '2026-10-09T12:53:28.908Z'
---

## Overview

A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the component jhttpd. The manipulation of the argument popupId leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

## Affected

- `di-7100g_c1_firmware = 2025-09-28`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
