D-Link DI-8100 Web Management Interface Stack-Based Buffer Overflow Vulnerability

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the D-Link DI-8100 router, specifically in the web management interface file '/url_member.asp'. This vulnerability arises from the 'name' parameter, which can be manipulated to overflow a fixed-size stack buffer. The issue can be exploited remotely, potentially leading to memory corruption, a process crash, and allowing for remote code execution.

Impact

Exploitation of this vulnerability causes memory corruption and process crashes, with the potential for remote code execution.

Reproduction

To reproduce this vulnerability, log into the router's web interface and navigate to the '/url_member.asp' page. Once there, initiate an 'add' operation by sending a POST request that includes a crafted 'name' parameter. This parameter should contain an excessively long string, which will overflow the stack buffer and trigger the vulnerability.

Added: May 5, 2026, 8:21 PM
Updated: May 5, 2026, 8:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
5.6
remediation
0.0
relevance
7.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.