Junglewise Threat Intelligence

CVE-2026-7855: D-Link DI-8100 buffer overflow in tggl_asp function

CVE-2026-7855 · Severity: high · CVSS 8.8 · Published 2026-05-05

Technologies: Dlink Di-8100, Dlink Di-8100 Firmware. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability exists in the D-Link DI-8100 router, a device used for managing small business and home network traffic. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could lead to a total loss of internet connectivity for the office or unauthorized access to internal network settings.

Technical details

A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8100 router firmware version 16.07.26A1. The vulnerability is located within the tggl_asp function of the HTTP Request Handler component, which processes requests to /tggl.asp. The flaw is triggered by unbounded sprintf and strcat operations on a fixed-size 10240-byte stack buffer when handling the 'Name' parameter during an 'opt=add' action. A remote attacker with low-level authentication can exploit this to crash the httpd service or achieve remote code execution on the MIPS-based architecture. A public proof-of-concept exploit has been disclosed.

Affected products

  • D-Link DI-8100 16.07.26A1

Timeline

  • 2026-05-05: disclosed
  • 2026-05-05: advisory

References

Related threats