{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3hdlinkdi-830016.07/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:dlink:di-8300:16.07:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-91003"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DI-8300 (16.07)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cve","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eD-Link DI-8300 version 16.07 is affected by a stack-based buffer overflow vulnerability (CVE-2026-91003) residing within the CGI service component. The vulnerability is triggered through the 'rzgl_asp' function located in the '/rzgl.asp' endpoint. By providing a specially crafted input to the 'redirct_url' argument, an unauthenticated remote attacker can cause a buffer overflow, potentially leading to arbitrary code execution or a denial of service on the device. Proof-of-concept exploit code has been publicly released, increasing the risk of exploitation by opportunistic threat actors. Organizations utilizing this hardware must restrict access to management interfaces to trusted network segments or isolate the devices until a firmware resolution is provided by the vendor.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary code with the privileges of the CGI service on the D-Link DI-8300 router. This could result in a full compromise of the device, enabling traffic interception, lateral movement into internal networks, or permanent denial of service. The vulnerability carries a CVSS v3.1 base score of 9.1, reflecting the severity of remote code execution on core network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the isolation of the D-Link DI-8300 management interface from the public internet. Ensure that network ingress to the device is restricted to trusted administrative IP addresses via firewall rules. Monitor internal logs for suspicious POST requests targeting '/rzgl.asp' with anomalous lengths in the 'redirct_url' parameter.\u003c/p\u003e\n","date_modified":"2026-09-15T07:39:21Z","date_published":"2026-09-15T07:39:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dlink-buffer-overflow/","summary":"A critical stack-based buffer overflow vulnerability in the D-Link DI-8300 CGI service enables remote code execution via a manipulated URL parameter.","title":"Remote Buffer Overflow Vulnerability in D-Link DI-8300","url":"https://feed.craftedsignal.io/briefs/2026-09-dlink-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:dlink:di-8300:16.07:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}