ZeroHour

CVE-2026-91001

moderate

Stack Buffer Overflow in D-Link DI-8400 16.07 DDNS Configuration

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

D-Link DI-8400 router firmware 16.07 contains a stack-based buffer overflow (CWE-121) in the ddns_asp function of the /ddns.asp DDNS Configuration page, reachable remotely through the web management interface. An attacker with low privileges (an authenticated session able to reach the DDNS settings) triggers the overflow by supplying overly long values in the serv, user, host, wild, mx, bmx, cust, or ip parameters, overwriting the stack and potentially executing arbitrary code on the router. Successful exploitation gives full control of the device, which typically sits at the network edge and can be used to intercept traffic, pivot inward, or enroll the router in botnets. Only D-Link DI-8400 running version 16.07 is reported affected; this is an older enterprise router primarily distributed in the Asian market. The VulDB description states an exploit has been disclosed publicly, but no confirmed public PoC is currently tracked and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so treat exploitation status as unconfirmed.

What to do: Check D-Link's security advisories for a firmware update for the DI-8400 and apply it if one exists; the device appears to be at or near end-of-support, so plan replacement if no patch is issued. Immediately remove the web management interface (/ddns.asp and the admin GUI) from internet exposure by restricting it to a trusted LAN segment or VPN, and audit the DDNS configuration and device logs for unexpected parameter values or unfamiliar admin sessions. Rotate admin credentials as a precaution if the device was exposed.

Affected
D-Link DI-8400
Estimated exposure
moderate≈ low thousands of internet-exposed devices (order of 1k–10k), rough estimate — Public internet scans (Shodan/Censys) have historically shown only a few thousand D-Link DI-8400 units with exposed management interfaces, consistent with a discontinued, regionally distributed enterprise router.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.