Executive brief
A security vulnerability has been identified in the D-Link DI-8100, a router used for managing business and home network traffic. An attacker can exploit this flaw to crash the device or potentially take control of it by sending specially crafted web requests. This could lead to a total loss of internet connectivity for the office or home, and may allow unauthorized access to the device's management settings.
Technical details
A stack-based buffer overflow exists in the D-Link DI-8100 Gigabit Router firmware version 16.07.26A1. The vulnerability is located in the 'url_rule_asp' function (at address 0x00481784) within the '/url_rule.asp' component. The root cause is the improper use of 'sprintf' to concatenate user-supplied POST parameters (such as 'name', 'ips', and 'time') into a fixed-size stack buffer of only 8 bytes without bounds checking. A remote attacker can exploit this by sending a crafted HTTP POST request to the web management interface, leading to memory corruption, denial-of-service (DoS), or potential remote code execution. Public exploit code has been disclosed.
Affected products
- D-Link DI-8100 Gigabit Router 16.07.26A1
Timeline
- 2026-05-05: disclosed: Initial disclosure via VulDB and NVD
- 2026-05-05: advisory