CVE-2026-101081Critical· 9.1▾ AbyssalPoC availableA security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt result…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.1 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
DI-8400 16.07Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91001Critical· 9.9A security flaw has been discovered in D-Link DI-8400 16.07
CVE-2026-94089Critical· 10.0A vulnerability was determined in D-Link DIR-868L 2.01b05
CVE-2026-91003Critical· 9.1A flaw has been found in D-Link DI-8300 16.07
CVE-2026-90693Critical· 9.9A flaw has been found in D-Link DIR-878 120B05
CVE-2026-86509Critical· 9.6A flaw has been found in D-Link DIR-895L A1_102b07
CVE-2026-86296Critical· 10.0A vulnerability was determined in D-Link DIR-822A A_101