Executive brief
A security vulnerability has been identified in the D-Link DI-8100 enterprise router. An attacker with administrative access can send a specially crafted request to the device's web management interface to cause a system crash or potentially take full control of the hardware. This could lead to a complete network outage or unauthorized access to sensitive corporate data passing through the router.
Technical details
A stack-based buffer overflow vulnerability exists in the D-Link DI-8100 firmware version 16.07.26A1. The flaw is located within the yyxz.asp endpoint, specifically due to an insecure call to the sprintf function when processing the 'id' parameter. The application fails to perform length validation before concatenating the user-supplied string with a prefix and writing it into a fixed-size stack buffer. A remote attacker with valid administrative credentials can exploit this by sending a long string in an HTTP POST request, leading to a service crash (DoS) or potential arbitrary code execution. A public proof-of-concept exploit is available.
Affected products
- D-Link DI-8100 16.07.26A1
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory