CVE-2026-91003
CRITICAL · 9.1Public exploit same-day, CRITICAL CVSS, but no KEV listing or confirmed in-the-wild yet.
What: Stack-based buffer overflow in D-Link DI-8300 16.07 CGI service (rzgl_asp function, redirct_url parameter) enabling remote code execution. CVSS 9.1 CRITICAL.
Why it matters: Public exploit available same day as disclosure. Remote unauthenticated RCE on network appliance. No KEV listing yet but exploit publication and CRITICAL score warrant immediate triage by D-Link device owners.
Where it's seen: Coordinated social amplification across threat intel feeds (Vulnsea, Hacker Wire, OffSeq radar) flagging exploit availability and RCE risk. Chatter focuses on patch urgency and network access restriction.
RISK: CRITICAL — Unauthenticated remote code execution on widely-deployed network device with public PoC.
Description
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- High
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High