CVE-2026-91003 Overview
CVE-2026-91003 is a stack-based buffer overflow in the D-Link DI-8300 router running firmware version 16.07. The flaw resides in the rzgl_asp function within the /rzgl.asp CGI service. Attackers can trigger the overflow by manipulating the redirct_url argument. Exploitation occurs over the network and a public proof-of-concept has been published, increasing the likelihood of opportunistic attacks against exposed devices. The weakness is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer).
Critical Impact
Successful exploitation can corrupt stack memory on the affected router, enabling arbitrary code execution or full device compromise from a network-adjacent position.
Affected Products
- D-Link DI-8300 router
- Firmware version 16.07
- CGI service handler rzgl.asp (function rzgl_asp)
Discovery Timeline
- 2026-09-15 - CVE-2026-91003 published to the National Vulnerability Database
- 2026-09-15 - Last updated in NVD database
Technical Details for CVE-2026-91003
Vulnerability Analysis
The vulnerability exists in the rzgl_asp handler exposed through the router's CGI service at /rzgl.asp. The handler accepts a redirct_url parameter from HTTP requests and copies its contents into a fixed-size stack buffer without validating the input length. Sending an overlong value overwrites adjacent stack memory, including saved return addresses and control data. Because the D-Link DI-8300 is an embedded network device, the affected process typically runs with elevated privileges, extending the impact from a local memory corruption issue to a remote foothold on the device. Public proof-of-concept material is available in the Xray CVE PoC repository, which lowers the barrier for weaponization.
Root Cause
The root cause is the absence of bounds checking when the rzgl_asp function processes the redirct_url request parameter. The CGI handler uses an unsafe string copy into a stack-allocated buffer, which allows attacker-controlled data to overrun the buffer and corrupt the surrounding stack frame. This pattern falls under CWE-119.
Attack Vector
Exploitation is performed remotely over the network by issuing a crafted HTTP request to the /rzgl.asp endpoint with an oversized redirct_url value. Per the published CVSS 4.0 vector, the attacker requires high privileges but no user interaction, and the impact spans confidentiality, integrity, and availability of both the vulnerable component and adjacent subsystems. A Python proof-of-concept demonstrating the request pattern is hosted in the Xray PoC script.
No verified exploit code is reproduced here. Refer to the VulDB entry for CVE-2026-91003 for technical details.
Detection Methods for CVE-2026-91003
Indicators of Compromise
- HTTP POST or GET requests to /rzgl.asp containing unusually long redirct_url parameter values (hundreds to thousands of bytes).
- Router web management process crashes, reboots, or watchdog resets correlating with inbound HTTP traffic.
- Unexpected outbound connections initiated by the router after receiving requests targeting the CGI service.
- Requests to /rzgl.asp originating from untrusted or WAN-facing source addresses.
Detection Strategies
- Deploy network intrusion detection signatures that flag HTTP requests to /rzgl.asp where the redirct_url argument exceeds a conservative length threshold.
- Inspect web application firewall or reverse proxy logs for repeated malformed requests targeting the CGI service.
- Correlate router syslog or crash reports with contemporaneous HTTP request logs to identify exploitation attempts.
Monitoring Recommendations
- Continuously monitor management-plane exposure of D-Link DI-8300 devices to identify unintended WAN accessibility of the web interface.
- Aggregate router logs into a centralized platform to correlate CGI request anomalies with device reboots and configuration changes.
- Track newly published proof-of-concept activity referenced in VulDB Vulnerability #403586 and adjust detections accordingly.
How to Mitigate CVE-2026-91003
Immediate Actions Required
- Restrict access to the router's web management interface to trusted internal networks and disable WAN-side administration.
- Change default and shared administrative credentials to reduce the chance of an attacker obtaining the privileges needed for exploitation.
- Inventory all D-Link DI-8300 devices running firmware 16.07 and prioritize them for remediation.
- Block or rate-limit external HTTP requests to /rzgl.asp at upstream network devices.
Patch Information
At the time of publication, no vendor patch is referenced in the NVD entry for CVE-2026-91003. Monitor the D-Link official website for firmware updates addressing the rzgl_asp handler. Until an official fix is available, apply the workarounds below and treat affected devices as high risk.
Workarounds
- Place affected DI-8300 devices behind a firewall that filters unsolicited inbound HTTP traffic to the management interface.
- Segment the router's management VLAN from user and guest networks to limit lateral reach if the device is compromised.
- If the CGI service is not required for business operations, restrict its reachability through access control lists on upstream equipment.
- Consider replacing end-of-support or unpatched hardware with vendor-supported alternatives if a firmware fix is not released.
# Example upstream ACL restricting access to the router web UI
# Replace 10.0.0.0/24 with your trusted management subnet
iptables -A FORWARD -p tcp -d <router_ip> --dport 80 -s 10.0.0.0/24 -j ACCEPT
iptables -A FORWARD -p tcp -d <router_ip> --dport 80 -j DROP
iptables -A FORWARD -p tcp -d <router_ip> --dport 443 -s 10.0.0.0/24 -j ACCEPT
iptables -A FORWARD -p tcp -d <router_ip> --dport 443 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
