CVE-2026-7851Disclosure(dlink / di-8100)

LOWCVSS 7.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • di-8100
  • di-8100_firmware

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-06-05)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
di-8100di-8100_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-05: 2Mentions · 2026-06-05: 3Technical Details · 2026-05-05: 2Technical Details · 2026-06-05: 305-0506-05
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-06-053
Disclosure3
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR CVE-2026-7851 exposes a critical stack-based buffer overflow in D-Link DI-8100 routers (firmware 16.07.26A1 and earlier). Attackers with admin access can trigger unauthenticated remote code execution via the yyxz.asp endpoint, converting the gateway from a network…

    Post summary

    The text discloses a critical stack‑based buffer overflow in D‑Link DI‑8100 routers (firmware 16.07.26A1 and earlier) that allows unauthenticated remote code execution via the yyxz.asp endpoint.

    1000041
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources CVE-2026-7851 (NVD): draw-ctf GitHub Report: CVE Record (http://CVE.org): The Gateway That Became the Backdoor: CVE-2026-7851 Turns D-Link DI-8100 Into a Remote Code Execution Engine

    Post summary

    The article announces a newly disclosed remote code execution vulnerability (CVE-2026-7851) affecting the D-Link DI-8100 router.

    1000042
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Gateway That Became the Backdoor: CVE-2026-7851 Turns D-Link DI-8100 Into a Remote Code Execution Engine. The vulnerable endpoint processes an id parameter with no input validation, allowing attackers to overflow the stack frame and gain arbitrary code execution on…

    Post summary

    The article reveals that D‑Link DI‑8100’s endpoint fails to validate the id parameter, causing a stack overflow that enables remote code execution, but no PoC, exploit code, or patch is provided.

    1000045
    246 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7851 A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-… https://www.cve.org/CVERecord?id=CVE-2026-7851

    Post summary

    The post announces the discovery of CVE-2026-7851 in a D‑Link device, describing a buffer overflow via the sprintf function in yyxz.asp, but does not provide exploit code, active exploitation evidence, or patch information.

    00001133
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7851 A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-… https://www.cve.org/CVERecord?id=CVE-2026-7851 ----- Traducción: CVE-2026-7851 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑7851, provides a brief technical description of a potential stack overflow via sprintf in a D‑Link router, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000031
    75 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdi-8100---
OSdlinkdi-8100_firmware16.07.26a1--

Explore more