CVE-2026-7851
published 2026-05-05CVE-2026-7851: A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads…
PriorityP261high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
4.08%
89.5th percentile
A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | di-8100 | — | — |
| dlink | di-8100_firmware | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.08.3HIGHAV:N/AC:L/Au:M/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
D-Link DI-8100 16.07.26A1 yyxz.asp sprintf ID stack-based overflow (EUVD-2026-27416 / CNNVD-202605-759)
vuldb·2026-05-07·CVSS 7.3
CVE-2026-7851 [HIGH] D-Link DI-8100 16.07.26A1 yyxz.asp sprintf ID stack-based overflow (EUVD-2026-27416 / CNNVD-202605-759)
A vulnerability marked as critical has been reported in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-7851. The attack is possible to be carried out remotely. Moreover, an exploit is present.
GHSA
GHSA-x4pj-ppv6-g6w7: A vulnerability was identified in D-Link DI-8100 16
ghsa_unreviewed·2026-05-05
CVE-2026-7851 [HIGH] CWE-119 GHSA-x4pj-ppv6-g6w7: A vulnerability was identified in D-Link DI-8100 16
A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-05
Published