A stack-based buffer overflow in the DDNS configuration handler of D-Link DI-8400 routers running firmware 16.07 can be triggered remotely by an authenticated low-privilege user, and working exploit code is already public.
What Is It
CVE-2026-91001 is a stack-based buffer overflow (CWE-121 / CWE-119) in the ddns_asp function of the file /ddns.asp, part of the DDNS Configuration component on the D-Link DI-8400. Manipulating any of the serv, user, host, wild, mx, bmx, cust, or ip arguments overflows a stack buffer. The attack can be initiated remotely, and per the NVD record the exploit has been released to the public and may be used for attacks.
Why It Matters
The CVSS v3.1 base score is 9.9 (CRITICAL) with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, and only low privileges required, with a scope change and total loss of confidentiality, integrity, and availability. The CVSS v4.0 assessment from the CNA scores it 8.6 (HIGH) and rates exploit maturity as PROOF_OF_CONCEPT. Public proof-of-concept code is published on GitHub, which lowers the bar for opportunistic attacks against internet-exposed devices.
No CISA KEV entry accompanies this CVE, so there is no confirmed evidence of active exploitation in the wild at this time; only publicly available exploit code.
What's Vulnerable
- Vendor: D-Link
- Product: DI-8400 (hardware;
cpe:2.3:h:d-link:di-8400) - Affected version: 16.07
- Component: DDNS Configuration,
ddns_aspin/ddns.asp
The supplied data lists only version 16.07 as affected; no other firmware versions are enumerated.
Patch Status
The source material does not identify a patched firmware release, vendor advisory, or required remediation action for this CVE. The only vendor reference supplied is D-Link's main website. Because no KEV entry exists, there is also no CISA-mandated due date or required action. Defenders should treat the device management interface as untrusted from the network side and restrict access to /ddns.asp and the wider admin UI until D-Link publishes guidance.
Sources
- NVD, CVE-2026-91001 record (source:
[email protected]), published 2026-09-15 - VulDB, CVE entry: https://vuldb.com/cve/CVE-2026-91001
- VulDB, vulnerability detail: https://vuldb.com/vuln/403582
- VulDB, threat intelligence: https://vuldb.com/vuln/403582/cti
- VulDB, submission record: https://vuldb.com/submit/931642
- Public exploit (Xray's CVE repo): https://github.com/Vivi-Xray/Xray-s-cve-/blob/main/ddns_asp/ddns_asp.py
- Public exploit directory: https://github.com/Vivi-Xray/Xray-s-cve-/tree/main/ddns_asp
- D-Link: https://www.dlink.com/