CVE-2026-91001
CRITICAL · 9.9Public exploit available day-one, CVSS 9.9, but KEV-not-yet-listed; active chatter suggests rapid weaponization risk.
What: Stack-based buffer overflow in D-Link DI-8400 16.07 DDNS configuration (CVE-2026-91001, CVSS 9.9 CRITICAL) allowing remote code execution via manipulation of multiple DDNS parameters.
Why it matters: Public exploit released same day as CVE publication; CVSS 9.9 indicates unauthenticated remote RCE on widely-deployed router hardware. Not yet KEV-listed but exploitation barrier is eliminated. Defenders managing D-Link deployments must triage immediately.
Where it's seen: Threat intelligence feeds and security media amplifying advisory within hours of publication; multiple posts emphasizing public exploit availability and criticality; limited but direct defender guidance (access restriction recommendations appearing).
RISK: CRITICAL — Unauthenticated RCE on router via public exploit; mass scanning likely imminent.
Description
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High