CVE-2026-7853
published 2026-05-05CVE-2026-7853: A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.9th percentile
A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | di-8100 | — | — |
| dlink | di-8100_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.9HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
D-Link DI-8100 16.07.26A1 HTTP /auto_reboot.asp sprintf enable/time buffer overflow (CNNVD-202605-758)
vuldb·2026-05-07·CVSS 8.9
CVE-2026-7853 [HIGH] D-Link DI-8100 16.07.26A1 HTTP /auto_reboot.asp sprintf enable/time buffer overflow (CNNVD-202605-758)
A vulnerability classified as critical has been found in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow.
The identification of this vulnerability is CVE-2026-7853. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
GHSA
GHSA-mrhg-43m6-jq5j: A weakness has been identified in D-Link DI-8100 16
ghsa_unreviewed·2026-05-05
CVE-2026-7853 [HIGH] CWE-119 GHSA-mrhg-43m6-jq5j: A weakness has been identified in D-Link DI-8100 16
A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-05
Published