Impact
A stack‑based buffer overflow in the Web Administration Service of the D‑Link DI‑8400 (firmware 16.07) is triggered by a malicious opt parameter sent to the menu_nat_more.asp endpoint. The overflow corrupts the stack, allowing an attacker to execute arbitrary code on the device, thereby compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects D‑Link DI‑8400 routers that are running firmware version 16.07. It is specific to the Web Administration Service component and the menu_nat_more.asp file; other firmware revisions or products are not known to be impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. Public exploits have been released, demonstrating that the flaw can be triggered remotely through the web interface. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the existence of documented exploits indicates a real‑world risk. Attackers can exploit the vulnerability from external networks by sending crafted requests to the vulnerable endpoint.
OpenCVE Enrichment