CVE-2025-1103 – D-Link DIR-823X HTTP POST Request Handler Null Pointer Dereference Remote Vulnerability

The following table lists the changes that have been made to the
CVE-2025-1103 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 07, 2025

    Action Type Old Value New Value
    Added Description A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the function set_wifi_blacklists of the file /goform/set_wifi_blacklists of the component HTTP POST Request Handler. The manipulation of the argument macList leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Added CVSS V2 (AV:N/AC:L/Au:S/C:N/I:N/A:C)
    Added CWE CWE-476
    Added CWE CWE-404
    Added Reference https://tasty-foxtrot-3a8.notion.site/D-link-DIR-823X-set_wifi_blacklists-Vulnerability-1870448e619580e5bf09cf628692f7a9?pvs=73
    Added Reference https://vuldb.com/?ctiid.294933
    Added Reference https://vuldb.com/?id.294933
    Added Reference https://vuldb.com/?submit.489603
    Added Reference https://www.dlink.com/
Share the Post:

Related Posts