Description
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-15
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack‑based buffer overflow exists in the ddns.asp component of the D‑Link DI‑8400 router, exposed through the DDNS configuration page. Crafting parameters such as serv, user, host, wild, mx overwrite control data on the stack, enabling an attacker to execute arbitrary code. This flaw is classified as CWE‑119 and CWE‑121 and carries a CVSS base score of 9.4, indicating critical severity.

Affected Systems

The vulnerability affects the D‑Link DI‑8400 router running firmware version 16.07. Any device that has not applied the latest firmware release containing a fix for the ddns.asp stack overflow is potentially exploitable. The issue is demonstrated on the /ddns.asp configuration page accessible via the router’s web interface.

Risk and Exploitability

The EPSS score is < 1 %, indicating low but non‑zero exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack can be initiated remotely, so the likely attack vector is remote. The CVE does not specify whether authentication is required, implying that the exploit could be performed from any remote source, whether or not credentials are present. Successful exploitation could grant the attacker remote code execution on the device, potentially compromising the network it protects.

Generated by OpenCVE AI on September 17, 2026 at 18:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the DI‑8400 firmware to a version that includes the ddns.asp stack overflow fix.
  • If a firmware update is not immediately available, disable the DDNS configuration feature or remove web access to the ddns.asp page on untrusted networks.
  • Restrict incoming connections to the router’s web administration interface to trusted IP ranges and apply firewall rules to block malformed requests.

Generated by OpenCVE AI on September 17, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Title D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow
First Time appeared D-link
D-link di-8400
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:h:d-link:di-8400:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link di-8400
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:20.155Z

Reserved: 2026-09-14T15:34:55.062Z

Link: CVE-2026-91001

cve-icon Vulnrichment

Updated: 2026-09-15T13:59:15.210Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:16:59.970

Modified: 2026-09-15T15:17:30.983

Link: CVE-2026-91001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow