Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-91001: D-Link DI-8400 can be crashed by remote request

CVE-2026-91001 · published 25 days ago
Summary

The DI-8400 router’s DDNS configuration page can be tricked into overflowing its memory when a specially crafted request is sent. An attacker on the network could cause the router to stop working or potentially take control. Update to the latest firmware or disable the DDNS feature until a fix is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link di-8400 16.07
Original advisory text
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument ...
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.6 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published15 Sep 2026
Updated7 Oct 2026
First seen15 Sep 2026
Sources
CVE-2026-91001 · MITRE
Track software like this
Free during beta