cbcvebase.

Dlink Di-8100 Firmware vulnerabilities

25 known vulnerabilities affecting dlink/di-8100_firmware.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH21MEDIUM3

Vulnerabilities

Page 1 of 2
CVE-2026-7853HIGHCVSS 8.9v16.07.26a12026-05-05
CVE-2026-7853 [HIGH] CWE-119 CVE-2026-7853: A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
nvd
CVE-2026-7854HIGHCVSS 8.9v16.07.26a12026-05-05
CVE-2026-7854 [HIGH] CWE-119 CVE-2026-7854: A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerabil A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler. Such manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-7851HIGHCVSS 7.3v16.07.26a12026-05-05
CVE-2026-7851 [HIGH] CWE-119 CVE-2026-7851: A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of th A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-7856HIGHCVSS 7.3v16.07.26a12026-05-05
CVE-2026-7856 [HIGH] CWE-119 CVE-2026-7856: A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_me A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing a manipulation of the argument Name can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
nvd
CVE-2026-7855HIGHCVSS 7.4v16.07.26a12026-05-05
CVE-2026-7855 [HIGH] CWE-119 CVE-2026-7855: A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tg A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. Performing a manipulation of the argument Name results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
nvd
CVE-2026-7857HIGHCVSS 7.3v16.07.26a12026-05-05
CVE-2026-7857 [HIGH] CWE-119 CVE-2026-7857: A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2026-7248HIGHCVSS 8.9v16.07.26a12026-04-28
CVE-2026-7248 [HIGH] CWE-119 CVE-2026-7248: A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
nvd
CVE-2026-7247HIGHCVSS 7.3v16.07.26a12026-04-28
CVE-2026-7247 [HIGH] CWE-119 CVE-2026-7247: A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-51281HIGHCVSS 7.0v16.07.26a12025-08-25
CVE-2025-51281 [HIGH] CWE-120 CVE-2025-51281: D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in th D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. This vulnerability allows authenticated attackers to cause a Denial of Service (DoS) by sending crafted GET requests with overly long values for these parameters.
nvd
CVE-2025-7911HIGHCVSS 7.4v1.02025-07-20
CVE-2025-7911 [HIGH] CWE-119 CVE-2025-7911: A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects t A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhttpd. The manipulation of the argument remove_ext_proto/remove_ext_port leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the pub
nvd
CVE-2025-7790HIGHCVSS 7.4v16.07.26a12025-07-18
CVE-2025-7790 [HIGH] CWE-119 CVE-2025-7790: A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This aff A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part of the file /menu_nat.asp of the component HTTP Request Handler. The manipulation of the argument out_addr/in_addr/out_port/proto leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has be
nvd
CVE-2025-7762HIGHCVSS 7.4v16.07.26a12025-07-17
CVE-2025-7762 [HIGH] CWE-119 CVE-2025-7762: A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some unknown processing of the file /menu_nat_more.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may
nvd
CVE-2025-7602HIGHCVSS 7.3v16.07.26a12025-07-14
CVE-2025-7602 [HIGH] CWE-119 CVE-2025-7602: A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affect A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7603HIGHCVSS 7.3v16.07.26a12025-07-14
CVE-2025-7603 [HIGH] CWE-119 CVE-2025-7603: A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-6881HIGHCVSS 7.4v16.07.212025-06-30
CVE-2025-6881 [HIGH] CWE-119 CVE-2025-6881: A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by thi A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pppoe_base.asp of the component jhttpd. The manipulation of the argument mschap_en leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be us
nvd
CVE-2025-5228HIGHCVSS 8.7≤ 202505232025-05-27
CVE-2025-5228 [HIGH] CWE-119 CVE-2025-5228: A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affe A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi of the component jhttpd. The manipulation of the argument notify leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to
nvd
CVE-2025-44083CRITICALCVSS 9.8v16.07.26a12025-05-21
CVE-2025-44083 [CRITICAL] CWE-287 CVE-2025-44083: An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authent An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication
nvd
CVE-2025-4544HIGHCVSS 7.5≤ 16.07.26a12025-05-11
CVE-2025-4544 [HIGH] CWE-119 CVE-2025-4544: A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of the component jhttpd. The manipulation of the argument def_max/def_time/def_tcp_max/def_tcp_time/def_udp_max/def_udp_time/def_icmp_max leads to stack-based buffer overflow. The attack may be initiate
nvd
CVE-2025-3538HIGHCVSS 8.7v16.07.26a12025-04-13
CVE-2025-3538 [HIGH] CWE-119 CVE-2025-3538: A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue af A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the component jhttpd. The manipulation of the argument callback leads to stack-based buffer overflow. The attack needs to be approached within the local network. The exploit has been disclosed to the pu
nvd
CVE-2025-28398HIGHCVSS 7.1v16.07.262025-04-01
CVE-2025-28398 [HIGH] CWE-120 CVE-2025-28398: D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the rem D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
nvd