CVE-2026-7855Disclosure(dlink / di-8100)

HIGHCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dlink di-8100 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. Performing a manipulation of the argument Name results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • di-8100
  • di-8100_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
di-8100di-8100_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 2Mentions · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-06: 1Exploit Tool / Code · 2026-06-06: 1Active Exploitation · 2026-06-06: 1Technical Details · 2026-05-05: 2Technical Details · 2026-06-06: 105-0506-06
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-06-061
Active Exploitation1
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Proof-of-Concept Status: Public exploits are actively circulating. Synergos Consultancy and RedPacket Security have published detailed technical breakdowns. TheHackerWire confirmed exploitation potential at CVSS 8.8 for CVE-2026-7855 with confirmed RCE impact.

    Post summary

    Public exploits for CVE‑2026‑7855 are circulating in the wild with confirmed RCE impact and a CVSS 8.8 rating, indicating active exploitation.

    1000095
    247 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7855 A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. … https://www.cve.org/CVERecord?id=CVE-2026-7855 ----- Traducción: CVE-2026-7855 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE-2026-7855, affecting the tggl_asp function in the D‑Link DI‑8100 is disclosed with technical details, but no PoC, exploit code, patch, or active exploitation activity is reported.

    0000031
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7855 A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. … https://www.cve.org/CVERecord?id=CVE-2026-7855

    Post summary

    The text announces detection of CVE‑2026‑7855 in a D‑Link device, detailing the affected function and file, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000140
    57.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdi-8100---
OSdlinkdi-8100_firmware16.07.26a1--

Explore more