SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91003

CRITICAL · CVSS 9.1 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability exists in the CGI Service of D-Link DI-8300 firmware version 16.07, specifically in the rzgl_asp function due to improper handling of the redirct_url argument. This critical flaw allows for remote exploitation, potentially enabling attackers to execute arbitrary code on affected devices. Organizations using the D-Link DI-8300 should prioritize immediate patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91003
Severity
CRITICAL
CVSS
9.1
EPSS
0.51%

Original NVD Description

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.