CVE-2026-94089Critical· 10.0▾ MidnightA vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lea…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91003Critical· 9.1A flaw has been found in D-Link DI-8300 16.07
CVE-2026-91001Critical· 9.9A security flaw has been discovered in D-Link DI-8400 16.07
CVE-2026-90680Critical· 9.9A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207
CVE-2026-90693Critical· 9.9A flaw has been found in D-Link DIR-878 120B05
CVE-2026-90692Critical· 9.9A vulnerability was detected in D-Link DIR-878 120B05
CVE-2026-86509Critical· 9.6A flaw has been found in D-Link DIR-895L A1_102b07