SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91001

CRITICAL · CVSS 9.9 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical stack-based buffer overflow vulnerability exists in the DDNS Configuration function of D-Link DI-8400 firmware version 16.07, allowing remote attackers to manipulate specific arguments and execute arbitrary code. This flaw poses a significant risk to the integrity and availability of affected devices, making it imperative for organizations using this router model to prioritize immediate patching or mitigation efforts. Users of D-Link DI-8400 should take action to secure their systems against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91001
Severity
CRITICAL
CVSS
9.9
EPSS
0.48%

Original NVD Description

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.