Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.5

CVE-2026-101081: D-Link DI-8400 router allows remote takeover via web admin

CVE-2026-101081 · published 4 days ago
Summary

The router’s web‑based settings page contains a coding mistake that can be triggered by sending specially crafted data, causing the device to run unintended code. An attacker who can reach the router over the network could use this to gain control of the router. Apply the latest firmware update from D‑Link or temporarily disable remote web administration until the fix is installed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link di-8400 16.07
Original advisory text
D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.5 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-101081 · MITRE
Track software like this
Free during beta