Junglewise Threat Intelligence

CVE-2026-10270: D-Link DI-7001 MINI stack overflow in httpd_debug.asp

CVE-2026-10270 · Severity: high · CVSS 8.8 · Published 2026-06-01

Vendors: D-Link.

Executive brief

A security vulnerability exists in D-Link DI-7001 MINI routers, which are devices used to manage network traffic for small businesses or home offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a total loss of internet connectivity or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the D-Link DI-7001 MINI-8G router firmware up to version 19.09.19A1. The flaw is located in the API component within the /httpd_debug.asp endpoint. The 'Time' parameter in HTTP POST requests is passed to the sprintf function without adequate length validation, allowing an attacker to overwrite the stack. While the attack requires low-level authentication (PR:L), it can be performed remotely over the network. Successful exploitation can result in a denial of service (DoS) or arbitrary command execution on the underlying operating system. A public exploit (PoC) is currently available.

Affected products

  • D-Link DI-7001 MINI-8G up to 19.09.19A1

Timeline

  • 2026-06-01: advisory: NVD publication date
  • 2026-06-01: disclosed: Public exploit code released on GitHub

References