OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101081

CRITICAL · CVSS 9.1 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical stack-based buffer overflow vulnerability exists in the Web Administration Service of D-Link DI-8400 devices, specifically within the menu_nat_more.asp file. This flaw allows remote attackers to manipulate the 'opt' argument, potentially leading to arbitrary code execution. Organizations using affected D-Link products should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101081
Severity
CRITICAL
CVSS
9.1
EPSS
0.54%

Original NVD Description

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.