Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-91001: D-Link DI-8400 can be crashed by remote request
CVE-2026-91001 · published 25 days ago
Summary
The DI-8400 router’s DDNS configuration page can be tricked into overflowing its memory when a specially crafted request is sent. An attacker on the network could cause the router to stop working or potentially take control. Update to the latest firmware or disable the DDNS feature until a fix is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | di-8400 | 16.07 |
Original advisory text
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument ...
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.6
High
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published15 Sep 2026
Updated7 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta