CVE-2026-101081
9.1 CRITICALpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI risk analysis
- Summary
- This vulnerability allows remote attackers to execute arbitrary code by manipulating the 'opt' argument, leading to a stack-based buffer overflow.
- Exploitability
- Exploitation is relatively straightforward given the public availability of an exploit. The attacker must be able to send a crafted request to the affected endpoint.
- Blast radius
- If exploited, this could result in complete control over the device, potentially leading to data theft, denial of service, or further attacks.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest firmware version 16.07 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-119, CWE-121
Public exploit & PoC references
All references
- https://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/manu_nat_more_asp.py
- https://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/menu_nat_more_asp_Stack%20Buffer%20Overflow.md
- https://vuldb.com/cve/CVE-2026-101081
- https://vuldb.com/submit/932318
- https://vuldb.com/vuln/410953
- https://vuldb.com/vuln/410953/cti
- https://www.dlink.com/
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-101074PoC
- HIGHCVE-2026-18895PoC
- HIGHCVE-2026-18897PoC
- HIGHCVE-2026-18898PoC
- CRITICALCVE-2026-94003PoC
- CRITICALCVE-2026-61486
- CRITICALCVE-2026-93738PoC
- CRITICALCVE-2026-95318
Related by shared AI tags and CWE weakness class. Browse the full archive.