CVE-2026-7853: D-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflow
A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /autoreboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7853?
CVE-2026-7853 has a high severity rating due to the potential for remote code execution via a buffer overflow.
How do I fix CVE-2026-7853?
To fix CVE-2026-7853, update the D-Link DI-8100 to the latest firmware version provided by the vendor.
What impact does CVE-2026-7853 have on my D-Link DI-8100 device?
CVE-2026-7853 can lead to unauthorized access or control over the device by exploiting the buffer overflow vulnerability.
Is there a workaround for CVE-2026-7853?
A possible workaround for CVE-2026-7853 is to disable HTTP access to the device until the firmware is updated.
What component is affected by CVE-2026-7853?
CVE-2026-7853 affects the HTTP Handler component, specifically the sprintf function in auto_reboot.asp.