CVE-2026-7853Disclosure(dlink / di-8100)

MEDIUMCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch dlink di-8100 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • di-8100
  • di-8100_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-05-05); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
di-8100di-8100_firmware

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-05-05: 3Mentions · 2026-05-07: 1Mentions · 2026-05-12: 1Mentions · 2026-05-15: 2Mentions · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-06: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-06-06: 1Technical Details · 2026-05-05: 3Technical Details · 2026-05-07: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-06: 105-0505-0705-1205-1506-06
Signal classification5 categories
Disclosure
337.5%
General
225.0%
Patch
112.5%
Active Exploitation
112.5%
PoC
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-053
Disclosure2Patch1
2026-05-071
Disclosure1
2026-05-121
Active Exploitation1
2026-05-152
General2
2026-06-061
PoC1
Full discourse8 posts
  • Solomon Neas@solomonneas
    Disclosure

    🟡 D-Link DI-8100 CVE-2026-7853 rated CVSS 8.9 NVD flags a high severity flaw in DI-8100 16.07.26A1. Inventory exposed edge devices and prioritize remediation. http://solomonneas.dev/intel

    Post summary

    The message announces the high‑severity CVE-2026-7853 affecting D‑Link DI‑8100 routers, urging inventory and remediation but provides no exploit or patch details.

    0101149
    92 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    TL;DR D-Link DI-8100 (firmware 16.07.26A1) contains three remote buffer overflow vulnerabilities with public exploit code. CVE-2026-7853 rates CVSS 10.0. No patches exist. Unauthenticated attackers can crash, disable, or potentially execute code on network edge devices…

    Post summary

    D‑Link DI‑8100 firmware has three remote buffer overflow bugs (CVE-2026-7853) rated CVSS 10.0, with public exploit code available and no patches released.

    1000050
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-7853 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    An advisory notes CVE-2026-7853 as critical, but lacks details on exploitation, mitigation, or solutions.

    1000035
    215 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7853 — CVSS 9.8/10 ██████████ A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/7fKyA3gDWh

    Post summary

    A critical vulnerability (CVE-2026-7853) affecting the sprintf function in D‑Link DI-8100 (CVSS 9.8/10) is disclosed, and a patch is now available.

    1000070
    28 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7853-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only references a URL and hashtags related to CVE‑2026‑7853, with no explicit details about PoC, exploitation, patches, or technical characteristics.

    0000021
    215 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting D-Link DI-8100 (CVE-2026-7853) https://vuldb.com/vuln/361130/cti

    Post summary

    CTI analysts report widespread attacks against D‑Link DI‑8100 (CVE‑2026‑7853), indicating active exploitation, while no patches, PoC, or technical details are disclosed.

    0000053
    2.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7853 A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulat… https://www.cve.org/CVERecord?id=CVE-2026-7853 ----- Traducción: CVE-2026-7853 Se … http://infoflow.cloud`

    Post summary

    The text announces a weakness in D-Link DI‑8100’s HTTP handler (specifically the sprintf function in /auto_reboot.asp). No PoC, exploit, or patch information is provided.

    0000030
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7853 A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulat… https://www.cve.org/CVERecord?id=CVE-2026-7853

    Post summary

    A new weakness in the D-Link DI-8100’s sprintf function within the HTTP Handler has been identified, but no exploitation or remediation details are included.

    00000124
    57.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdi-8100---
OSdlinkdi-8100_firmware16.07.26a1--

Explore more