Vulnerability Description
A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Di-8100 Firmware | 16.07.26a1 |
| Dlink | Di-8100 | - |
Related Weaknesses (CWE)
References
- https://github.com/draw-ctf/report/blob/main/DI-8100/file_exten_asp_overflow.mdExploitThird Party Advisory
- https://vuldb.com/submit/802868Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359856Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359856/ctiPermissions RequiredVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2026-7247?
CVE-2026-7247 is a vulnerability with a CVSS score of 7.2 (HIGH). A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation ...
How severe is CVE-2026-7247?
CVE-2026-7247 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7247?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Di-8100 Firmware, Dlink Di-8100.