Description
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Published: 2026-09-15
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Stack-Based Buffer Overflow
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the CGI service of the D-Link DI-8300, specifically within the rzgl_asp function handled by /rzgl.asp. An attacker can manipulate the redirct_url argument to trigger a stack-based buffer overflow CWE‑121. Remote exploitation is feasible and an exploit has already been published, indicating a high likelihood of real-world attacks.

Affected Systems

D-Link DI‑8300 devices running firmware version 16.07 are affected. No other versions are listed as impacted in the current advisory.

Risk and Exploitability

The CVSS score of 9.4 classifies this flaw as critical, though the EPSS suggesting a low yet non‑zero probability of exploitation on a broad scale. Because the attack vector is remote and mediated through web interface requests to /rzgl.asp, adversaries can target any exposed device without authentication. The advisory does not list this CVE in the CISA KEV catalog, but the presence of an existing exploit mandates that administrators treat it with the same urgency as KEV‑listed threats.

Generated by OpenCVE AI on September 17, 2026 at 18:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the DI‑8300 that patches the CGI service; if no update is available, block or disable HTTP access to /rzgl.asp using a firewall or router ACL to prevent external requests to the vulnerable endpoint.
  • Implement network segmentation and enforce strict ingress filtering for web admin traffic, and consider a web application firewall that rejects overly long or.
  • Verify that the vulnerable CGI endpoint is not exposed to the Internet by scanning for open HTTP ports or attempting a harmless request, and if exposed, isolate the device behind a DMZ or implement monitoring to detect exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Title D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow
First Time appeared D-link
D-link di-8300
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:h:d-link:di-8300:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link di-8300
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:05:24.781Z

Reserved: 2026-09-14T15:47:25.367Z

Link: CVE-2026-91003

cve-icon Vulnrichment

Updated: 2026-09-15T14:05:01.215Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:17:01.387

Modified: 2026-09-15T15:17:31.133

Link: CVE-2026-91003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow