Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101081 2026-09-28

D-Link DI-8400 Stack Overflow in Web Admin NAT Page (CVE-2026-101081)

"CVE-2026-101081 is a remotely triggerable stack-based buffer overflow in the web administration service of the D-Link DI-8400 running version 16.07, and a public exploit has been released."

CVE-2026-101081 is a remotely triggerable stack-based buffer overflow in the web administration service of the D-Link DI-8400 running version 16.07, and a public exploit has been released.

What Is It

The flaw is in the menu_nat_more_asp function of menu_nat_more.asp, part of the DI-8400's Web Administration Service. An attacker who manipulates the opt argument can cause a stack-based buffer overflow. The weakness is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-121 (Stack-based Buffer Overflow). VulDB, as the CNA, published the CVE on 2026-09-28. NVD currently lists its status as "Deferred."

Why It Matters

The CNA gives it a CVSS 3.1 base score of 9.1 (Critical), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The CVSS 4.0 score is 8.5 (High), with exploit maturity marked as Proof-of-Concept. The attack works over the network, has low complexity and needs no user interaction. However, it requires high privileges, so an attacker would need administrative access to the web interface first.

CISA's SSVC assessment lists exploitation as "poc", automatable as "no" and technical impact as "total." The advisory says the exploit "has been released to the public and may be used for attacks," and the NVD references include a public PoC script and write-up.

KEV status: The supplied CISA KEV entry is empty. This CVE is not in the Known Exploited Vulnerabilities catalog, and there is no confirmation of active exploitation in the wild.

What's Vulnerable

The source data does not list any other affected versions.

Patch Status

The supplied KEV and NVD records do not mention a vendor patch, fixed firmware version or official advisory. The only vendor reference is D-Link's general homepage. There is no CISA required action or due date because the CVE is not in KEV.

Until D-Link publishes fix guidance, administrators should restrict access to the DI-8400 web management interface and make sure administrative credentials are protected. The CVE needs high privileges to exploit, so both steps directly limit who can trigger it.

Sources