{"id":"CVE-2026-101081","published":"2026-09-28T17:17:47.817","lastModified":"2026-09-28T21:03:44.987","description":"A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-119","CWE-121"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/manu_nat_more_asp.py","tags":[]},{"url":"https://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/menu_nat_more_asp_Stack%20Buffer%20Overflow.md","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-101081","tags":[]},{"url":"https://vuldb.com/submit/932318","tags":[]},{"url":"https://vuldb.com/vuln/410953","tags":[]},{"url":"https://vuldb.com/vuln/410953/cti","tags":[]},{"url":"https://www.dlink.com/","tags":[]}],"exploitRefs":[{"url":"https://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/manu_nat_more_asp.py","tags":[]},{"url":"https://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/menu_nat_more_asp_Stack%20Buffer%20Overflow.md","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows remote attackers to execute arbitrary code by manipulating the 'opt' argument, leading to a stack-based buffer overflow.","exploitability":"Exploitation is relatively straightforward given the public availability of an exploit. The attacker must be able to send a crafted request to the affected endpoint.","blast_radius":"If exploited, this could result in complete control over the device, potentially leading to data theft, denial of service, or further attacks.","remediation":"Upgrade to the latest firmware version 16.07 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","buffer-overflow"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:54:07.187Z"}}