Executive brief
A critical security vulnerability has been identified in the D-Link DI-8100 router, a device used for managing network connectivity. An attacker can remotely exploit this flaw to crash the router or potentially take full control of the device. This could lead to unauthorized access to sensitive data, redirection of internet traffic, or a complete loss of internet service for the affected network.
Technical details
A stack-based buffer overflow (CWE-120) exists in the HTTP Handler component of the D-Link DI-8100 router, specifically within the auto_reboot_asp function (address 0x0042a180). The vulnerability is caused by the unsafe use of the sprintf() function when processing the 'enable' and 'time' parameters retrieved from NVRAM. Because these parameters are derived from user-controlled HTTP POST requests to /auto_reboot.asp without length validation, an attacker can provide overly long strings that overwrite the stack buffer (acStack_90). This can lead to the corruption of the function's return address, enabling remote code execution (RCE) or a crash of the jhttpd daemon. Public exploit code is available.
Affected products
- D-Link DI-8100 16.07.26A1
Timeline
- 2026-05-05: disclosed: Vulnerability disclosed and CVE assigned
- 2026-05-05: advisory: Initial advisory published by VulDB