peter bassill · operator
$ cve CVE-2026-7248 JSON

CVE-2026-7248

9.8
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.78% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2026-04-28
Last modified2026-06-17

Affected (2)

VendorProduct
dlinkdi-8100
dlinkdi-8100 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD