CVE-2026-7857
גבוהה 7.2
תיאור (מקור, אנגלית)
A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
7.3 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 4% (אחוזון 100) נכון ל-31/7/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
dlink: di-8100 firmware; dlink: di-8100
קישורים
- https://github.com/draw-ctf/report/blob/main/DI-8100/user_group_asp_overflow.md ExploitThird Party Advisory
- https://vuldb.com/submit/807853 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/361134 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/361134/cti Permissions RequiredVDB Entry
- https://www.dlink.com/ Product