Impact
The vulnerability resides in the CGI service of the D-Link DI-8300, specifically within the rzgl_asp function handled by /rzgl.asp. An attacker can manipulate the redirct_url argument to trigger a stack-based buffer overflow CWE‑121. Remote exploitation is feasible and an exploit has already been published, indicating a high likelihood of real-world attacks.
Affected Systems
D-Link DI‑8300 devices running firmware version 16.07 are affected. No other versions are listed as impacted in the current advisory.
Risk and Exploitability
The CVSS score of 9.4 classifies this flaw as critical, though the EPSS suggesting a low yet non‑zero probability of exploitation on a broad scale. Because the attack vector is remote and mediated through web interface requests to /rzgl.asp, adversaries can target any exposed device without authentication. The advisory does not list this CVE in the CISA KEV catalog, but the presence of an existing exploit mandates that administrators treat it with the same urgency as KEV‑listed threats.
OpenCVE Enrichment