CVE-2026-7248
קריטית 9.4
תיאור (מקור, אנגלית)
A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
מדדים
- CVSS 3.1
-
9.4 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H - CVSS 4.0
-
8.9 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
dlink: di-8100 firmware; dlink: di-8100
קישורים
- https://github.com/draw-ctf/report/blob/main/DI-8100/DI-8100_tgfile_htm_overfl… ExploitThird Party Advisory
- https://vuldb.com/submit/802869 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359857 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359857/cti Permissions RequiredVDB Entry
- https://www.dlink.com/ Product