CVE-2026-91001: D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddnsasp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely, but the CVSS vector indicates low privileges are required. No user interaction is required.
Which inputs are involved in the vulnerable request?
The affected ddns.asp handler processes the serv, user, host, wild, mx, bmx, cust, and ip arguments. Manipulating these arguments can trigger a stack-based buffer overflow in ddns_asp.
Is public exploit code available?
Yes. The available data states that an exploit has been released publicly and may be used in attacks.
How can I determine whether a device is affected?
The reported affected version is D-Link DI-8400 16.07, specifically its DDNS Configuration component and the /ddns.asp endpoint. Review the device model and installed firmware version, and identify whether this endpoint is present.