CVE-2026-7854

CRITICAL

D-Link DI-8100 POST Parameter url_rule.asp url_rule_asp buffer overflow

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler. Such manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

References (5)

Core 5
Core References
Product product
https://www.dlink.com/
Vdb Entry, Technical Description vdb-entry technical-description
VDB-361131 | D-Link DI-8100 POST Parameter url_rule.asp url_rule_asp buffer overflow
https://vuldb.com/vuln/361131
Signature, Permissions Required signature permissions-required
VDB-361131 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/361131/cti
Third Party Advisory third-party-advisory
Submit #807838 | D-Link DI-8100 16.07.26A1 Denial of Service
https://vuldb.com/submit/807838

Scores

CVSS v3 9.8
EPSS 0.0010
EPSS Percentile 26.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (2)
D-Link/DI-8100 16.07.26A1
dlink/di-8100_firmware 16.07.26a1
Published May 05, 2026
Tracked Since May 06, 2026