CVE-2026-101081
Received Received - Intake

Stack-Based Buffer Overflow in D-Link DI-8400 Web Admin

Vulnerability report for CVE-2026-101081, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
d-link di-8400 16.07

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101081 is a stack-based buffer overflow in D-Link DI-8400 16.07's Web Administration Service. The flaw occurs in the menu_nat_more_asp function when processing the opt argument via unsafe functions like sprintf and strcat. Attackers can send maliciously crafted HTTP POST requests with excessively long strings to overflow fixed-size stack buffers, potentially overwriting the return address and enabling arbitrary code execution.

Detection Guidance

To detect this vulnerability, monitor network traffic for unusually large HTTP POST requests targeting /menu_nat_more.asp with parameters like src, src_addr, or target_addr exceeding normal lengths. Check for crashes or unexpected behavior in the web administration service of D-Link DI-8400 devices.

Impact Analysis

This vulnerability allows remote attackers to execute arbitrary code on the device, potentially leading to full system compromise. It may result in exposure of sensitive data, persistent denial-of-service, or enable pivoting attacks within the local network. Exploitation requires administrative privileges or bypassing authentication.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or device compromise, which may violate GDPR (data protection) and HIPAA (health data security) requirements for confidentiality and integrity. Exploitation risks exposure of sensitive data, persistent denial-of-service, or network pivoting, all of which could result in non-compliance with these regulations.

Mitigation Strategies

Immediately update the device firmware if a patch is available. Restrict access to the administrative interface by IP whitelisting or disabling remote access. Limit POST payload sizes and implement input validation for all parameters. Consider deploying a WAF to filter malicious requests targeting this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101081. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart