← back

CVE-2026-91003

CRITICAL · 9.1
hype LIKELY HACK · 72 hack

Public exploit same-day, CRITICAL CVSS, but no KEV listing or confirmed in-the-wild yet.

What: Stack-based buffer overflow in D-Link DI-8300 16.07 CGI service (rzgl_asp function, redirct_url parameter) enabling remote code execution. CVSS 9.1 CRITICAL.

Why it matters: Public exploit available same day as disclosure. Remote unauthenticated RCE on network appliance. No KEV listing yet but exploit publication and CRITICAL score warrant immediate triage by D-Link device owners.

Where it's seen: Coordinated social amplification across threat intel feeds (Vulnsea, Hacker Wire, OffSeq radar) flagging exploit availability and RCE risk. Chatter focuses on patch urgency and network access restriction.

RISK: CRITICAL — Unauthenticated remote code execution on widely-deployed network device with public PoC.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/15/2026, 3:23:12 PM

Description

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS 3.1 breakdown

Exploitability 2.3 · Impact 6.0
vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Weaknesses