Impact
A stack‑based buffer overflow exists in the ddns.asp component of the D‑Link DI‑8400 router, exposed through the DDNS configuration page. Crafting parameters such as serv, user, host, wild, mx overwrite control data on the stack, enabling an attacker to execute arbitrary code. This flaw is classified as CWE‑119 and CWE‑121 and carries a CVSS base score of 9.4, indicating critical severity.
Affected Systems
The vulnerability affects the D‑Link DI‑8400 router running firmware version 16.07. Any device that has not applied the latest firmware release containing a fix for the ddns.asp stack overflow is potentially exploitable. The issue is demonstrated on the /ddns.asp configuration page accessible via the router’s web interface.
Risk and Exploitability
The EPSS score is < 1 %, indicating low but non‑zero exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack can be initiated remotely, so the likely attack vector is remote. The CVE does not specify whether authentication is required, implying that the exploit could be performed from any remote source, whether or not credentials are present. Successful exploitation could grant the attacker remote code execution on the device, potentially compromising the network it protects.
OpenCVE Enrichment