CVE-2026-7247
גבוהה 7.2
תיאור (מקור, אנגלית)
A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
7.3 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
dlink: di-8100 firmware; dlink: di-8100
קישורים
- https://github.com/draw-ctf/report/blob/main/DI-8100/file_exten_asp_overflow.md ExploitThird Party Advisory
- https://vuldb.com/submit/802868 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359856 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359856/cti Permissions RequiredVDB Entry
- https://www.dlink.com/ Product