A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/draw-ctf/report/blob/main/DI-8100/user_group_asp_overflow.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/807853 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/361134 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/361134/cti | Permissions Required VDB Entry |
| https://www.dlink.com/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
06 May 2026, 17:28
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:di-8100_firmware:16.07.26a1:*:*:*:*:*:*:* |
|
| References | () https://github.com/draw-ctf/report/blob/main/DI-8100/user_group_asp_overflow.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/807853 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/361134 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/361134/cti - Permissions Required, VDB Entry | |
| References | () https://www.dlink.com/ - Product | |
| First Time |
Dlink di-8100 Firmware
Dlink di-8100 Dlink |
05 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 20:16
Updated : 2026-05-06 17:28
NVD link : CVE-2026-7857
Mitre link : CVE-2026-7857
CVE.ORG link : CVE-2026-7857
JSON object : View
Products Affected
dlink
- di-8100_firmware
- di-8100
