CVE-2026-91003
nicheStack-Based Buffer Overflow in D-Link DI-8300 Router CGI Service (rzgl.asp)
A remotely exploitable stack-based buffer overflow exists in the rzgl_asp function of the /rzgl.asp CGI handler in D-Link DI-8300 firmware 16.07. An attacker triggers the flaw by sending an overly long value in the redirct_url argument to the router's web-based CGI service, overflowing a stack buffer. Successful exploitation can yield full compromise of the router with high impact to confidentiality, integrity, and availability, and the CVSS:4.0 vector (8.5, AV:N/PR:H) suggests the attacker needs privileged (e.g., authenticated admin-level) access to the management interface. Only D-Link DI-8300 running version 16.07 is confirmed affected. The advisory notes an exploit may have been published, but no public proof-of-concept is confirmed and there is no evidence of exploitation in the wild or a CISA KEV listing.
What to do: Immediately remove the DI-8300's web management interface from internet exposure by restricting access to trusted LAN/VPN segments via firewall rules or ACLs, since no fixed firmware version is identified in the advisory. Check device logs and crash history for anomalous requests to /rzgl.asp containing unusually long redirct_url parameters, which would indicate exploit attempts. Given the age of the DI-8300 platform, plan to replace it with a currently supported router, as D-Link legacy models frequently stop receiving security patches.
| D-Link DI-8300 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
- Weakness
- CWE-119, CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.