CVE-2026-7854
קריטית 9.8
תיאור (מקור, אנגלית)
A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler. Such manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
8.9 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-28/9/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
dlink: di-8100 firmware; dlink: di-8100
קישורים
- https://github.com/draw-ctf/report/blob/main/DI-8100/url_rule_asp_overflow.md ExploitThird Party Advisory
- https://vuldb.com/submit/807838 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/361131 Third Party Advisory
- https://vuldb.com/vuln/361131/cti Permissions RequiredVDB Entry
- https://www.dlink.com/ Product