CVE-2026-7855
8.8D-Link · DI-8100
A buffer overflow vulnerability exists in the D-Link DI-8100 router firmware via the tggl.asp component, allowing authenticated attackers to cause a denial of service or remote code execution.
Executive summary
A critical stack-based buffer overflow vulnerability in the D-Link DI-8100 router firmware allows authenticated remote attackers to trigger memory corruption and system compromise.
Vulnerability
This is a buffer overflow vulnerability (CWE-120) located in the tggl_asp function of the /tggl.asp HTTP Request Handler, triggered by manipulating the Name parameter with low privileges required.
Business impact
A successful exploit of this vulnerability can lead to a complete denial of service by crashing the router web management service or forcing a device reboot, disrupting network operations. Furthermore, memory corruption vulnerabilities on embedded router devices can potentially enable remote code execution, granting attackers full administrative control over the underlying networking hardware. The high CVSS score of 8.8 reflects the severity of potential total system impact and loss of availability.
Remediation
Immediate Action: Apply firmware updates provided by D-Link as soon as they become available to address the underlying memory corruption flaw.
Proactive Monitoring: Monitor network and administrative logs for unusual crashes of the web management service or repeated authentication attempts followed by suspicious request payloads.
Compensating Controls: Restrict administrative access to the router management interface to trusted internal network segments and disable external management exposure.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exploit exists via a referenced GitHub repository containing a functional Python script.
Analyst recommendation
Given the critical severity and the availability of a public proof-of-concept exploit, administrators must treat this issue with high urgency. Restrict administrative access immediately while monitoring vendor channels for official firmware patches to secure affected routing hardware.
More D-Link CVEs
Sources
Originally found and disclosed by draw (VulDB User), per the CVE Program record.
- VDB-361132 | D-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflow Vulnerability database entry
- VDB-361132 | CTI Indicators (IOB, IOC, IOA)
- Submit #807841 | D-Link DI-8100 16.07.26A1 Denial of Service Third-party advisory
- Exploit / PoC
- dlink.com