Description
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-20
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Firmware Update
AI Analysis

Impact

The vulnerability exists in the Authentication Handler component of D‑Link DIR‑868L firmware 2.01b05, where the strcpy function copies user supplied id and password values into a fixed-size buffer. Manipulating these arguments can trigger a stack‑based buffer overflow (CWE‑119) that, due to stack corruption (CWE‑121), may allow an attacker to execute arbitrary code on the device. Because the vulnerable code is invoked when the web authentication page is accessed, the resulting impact is remote code execution, potentially granting full control over the device and any network resources it is connected to.

Affected Systems

The affected product is D‑Link DIR‑868L, firmware revision 2.01b05. No additional vendor or product variants are specified.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. The EPSS score is not available, but the exploit is publicly disclosed and can be performed over the web interface, meaning it can be launched remotely. The vulnerability is not listed in the CISA KEV catalog; however, the combination of a high CVSS score, remote attack vector, and publicly available exploit script raises the likelihood of real‑world exploitation. An attacker could leverage the stack overflow to inject and execute code, leading to full device compromise, data exfiltration, or further network intrusion.

Generated by OpenCVE AI on September 20, 2026 at 23:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and apply any available firmware updates from the vendor that may address the vulnerability.
  • Disable or restrict external access to the device’s web authentication interface by applying firewall rules or limiting the interface to trusted IP addresses.
  • Block the device’s HTTP/HTTPS ports from untrusted networks, ensuring that only authorized management traffic is allowed to reach the web interface.

Generated by OpenCVE AI on September 20, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Title D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow
First Time appeared D-link
D-link dir-868l
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:h:d-link:dir-868l:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dir-868l
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:42:13.561Z

Reserved: 2026-09-20T08:02:24.652Z

Link: CVE-2026-94089

cve-icon Vulnrichment

Updated: 2026-09-22T15:36:56.027Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T21:16:55.780

Modified: 2026-09-22T16:18:16.913

Link: CVE-2026-94089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow