CNNVD-202509-647 Information

CNNVD ID

CNNVD-202509-647

CVE-2025-9938

  • CNNVD Published: 2025-09-04

Description (Chinese)

D-Link DI-8400是中国友讯(D-Link)公司的一款无线路由器。 D-Link DI-8400 16.07.26A1版本存在安全漏洞,该漏洞源于文件/yyxz.asp中参数ID操作不当,可能导致栈缓冲区溢出攻击。

Description (English)

D-Link DI-8400 is a wireless router for the Chinese company D-Link. 16.07.26A1 version of D-Link DI-8400 16.07.26A1 contains a security loophole, which stems from the inappropriate operation of parameter ID in document/yxz.asp, which could lead to a spill-out of the buffer zone.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

D3D

Published

2025-09-04

Last Modified

2026-02-24

References

https://github.com/ZZ2266/.github.io/tree/main/Dlink/DI-8400/yyxz.asp https://github.com/ZZ2266/.github.io/tree/main/Dlink/DI-8400/yyxz.asp#proof-of-concept-poc https://vuldb.com/?ctiid.322340 https://vuldb.com/?id.322340 https://vuldb.com/?submit.643446 https://www.dlink.com/

Share on: