CVE-2026-7247
published 2026-04-28CVE-2026-7247: A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component…
PriorityP353high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.72%
50.0th percentile
A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | di-8100 | — | — |
| dlink | di-8100_firmware | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.08.3HIGHAV:N/AC:L/Au:M/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8j59-4p62-3qc9: A vulnerability has been found in D-Link DI-8100 16
ghsa_unreviewed·2026-04-28
CVE-2026-7247 [HIGH] CWE-119 GHSA-8j59-4p62-3qc9: A vulnerability has been found in D-Link DI-8100 16
A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
VulDB
D-Link DI-8100 16.07.26A1 File Extension file_exten.asp file_exten_asp Name buffer overflow
vuldb·2026-04-27·CVSS 7.3
CVE-2026-7247 [HIGH] D-Link DI-8100 16.07.26A1 File Extension file_exten.asp file_exten_asp Name buffer overflow
A vulnerability classified as critical has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow.
This vulnerability is referenced as CVE-2026-7247. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-28
Published