CVE-2026-91003: D-Link Di-8300
Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected products
- D-Link Di-8300: version 16.07 only
Published 2026-09-15. Last modified 2026-09-15.