CVE-2024-52711
MEDIUMD-Link DI-8100 Firmware 16.07.26A1 - Buffer Overflow in ip_position_asp via ip Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-52711. PoCs published by 14mb1v45h.
AI-analyzed exploit summary This PoC exploits a buffer overflow vulnerability in a web interface by sending a large payload to the 'ip' parameter in 'ip_position.asp'. It first authenticates with default credentials before triggering the overflow.
Description
DI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter.
Exploits (1)
nomisec
WORKING POC
by 14mb1v45h · poc
https://github.com/14mb1v45h/cyberspace-CVE-2024-52711
This PoC exploits a buffer overflow vulnerability in a web interface by sending a large payload to the 'ip' parameter in 'ip_position.asp'. It first authenticates with default credentials before triggering the overflow.
Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target:
Unknown (likely a router or embedded device with web interface)
Auth required
Prerequisites:
Network access to the target · Default credentials (admin:admin)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://github.com/CLan-nad/CVE/blob/main/D-Link/ip_position_asp/1.md
Scores
CVSS v3
5.7
EPSS
0.0060
EPSS Percentile
44.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-120
Status
published
Products (1)
dlink/di-8100_firmware
16.07.26a1
Published
Nov 19, 2024
Tracked Since
Feb 18, 2026