Description
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-28
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack‑based buffer overflow in the Web Administration Service of the D‑Link DI‑8400 (firmware 16.07) is triggered by a malicious opt parameter sent to the menu_nat_more.asp endpoint. The overflow corrupts the stack, allowing an attacker to execute arbitrary code on the device, thereby compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects D‑Link DI‑8400 routers that are running firmware version 16.07. It is specific to the Web Administration Service component and the menu_nat_more.asp file; other firmware revisions or products are not known to be impacted.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. Public exploits have been released, demonstrating that the flaw can be triggered remotely through the web interface. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the existence of documented exploits indicates a real‑world risk. Attackers can exploit the vulnerability from external networks by sending crafted requests to the vulnerable endpoint.

Generated by OpenCVE AI on September 28, 2026 at 18:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the D‑Link DI‑8400 that patches the stack‑based buffer overflow in the Web Administration Service.
  • Configure firewall rules or router ACLs to restrict access to the Web Administration Service to trusted administrative IP ranges.
  • If an update is not available, block the menu_nat_more.asp endpoint or disable the Web Administration interface to prevent remote exploitation.

Generated by OpenCVE AI on September 28, 2026 at 18:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Title D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow
First Time appeared D-link
D-link di-8400
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:h:d-link:di-8400:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link di-8400
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T16:47:58.730Z

Reserved: 2026-09-27T18:19:51.095Z

Link: CVE-2026-101081

cve-icon Vulnrichment

Updated: 2026-09-28T16:47:52.443Z

cve-icon NVD

Status : Received

Published: 2026-09-28T17:17:47.817

Modified: 2026-09-28T17:17:47.817

Link: CVE-2026-101081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow