CVE-2026-10270: D-Link Di-7001mini-8g Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

Affected products

  • D-Link Di-7001mini-8g Firmware: version 19.09.19a1 only

Published 2026-06-01. Last modified 2026-07-22.