CVE-2026-7853: D-Link Di-8100 Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

  • D-Link Di-8100 Firmware: version 16.07.26a1 only

Published 2026-05-05. Last modified 2026-07-24.