CVE-2025-8175

A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument share_enable leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:di-8400_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8400:a1:*:*:*:*:*:*:*

History

16 Sep 2025, 18:34

Type Values Removed Values Added
References () https://github.com/Kriswu1337/CVE/blob/main/DI_8400%20Null%20pointer%20dereference%20vulnerability.md - () https://github.com/Kriswu1337/CVE/blob/main/DI_8400%20Null%20pointer%20dereference%20vulnerability.md - Exploit
References () https://vuldb.com/?ctiid.317589 - () https://vuldb.com/?ctiid.317589 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.317589 - () https://vuldb.com/?id.317589 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.621708 - () https://vuldb.com/?submit.621708 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product
CPE cpe:2.3:o:dlink:di-8400_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8400:a1:*:*:*:*:*:*:*
First Time Dlink
Dlink di-8400 Firmware
Dlink di-8400

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en D-Link DI-8400 16.07.26A1. Se ha clasificado como problemática. Afecta a una parte desconocida del archivo usb_paswd.asp del componente jhttpd. La manipulación del argumento share_enable provoca la desreferenciación de puntero nulo. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado.

28 Jul 2025, 16:15

Type Values Removed Values Added
References () https://github.com/Kriswu1337/CVE/blob/main/DI_8400%20Null%20pointer%20dereference%20vulnerability.md - () https://github.com/Kriswu1337/CVE/blob/main/DI_8400%20Null%20pointer%20dereference%20vulnerability.md -

26 Jul 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-26 03:15

Updated : 2025-09-16 18:34


NVD link : CVE-2025-8175

Mitre link : CVE-2025-8175

CVE.ORG link : CVE-2025-8175


JSON object : View

Products Affected

dlink

  • di-8400
  • di-8400_firmware
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-476

NULL Pointer Dereference