CVE-2026-101081
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_
CVSS
9.1
Crítico
EPSS
0.5%
p43
KEV
—
Exploit Today
13
0-100
Publicado: 28 sept 2026 · Última mod.: 28 sept 2026 · CWE-119 · CWE-121
Sin historial EPSS suficiente todavía.
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
- github.comhttps://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/manu_nat_more_asp.py
- github.comhttps://github.com/Vivi-Xray/Xray-s-cve-/blob/main/menu_nat_more_asp/menu_nat_more_asp_Stack%20Buffer%20Overflow.md
- vuldb.comhttps://vuldb.com/cve/CVE-2026-101081
- vuldb.comhttps://vuldb.com/submit/932318
- vuldb.comhttps://vuldb.com/vuln/410953
- vuldb.comhttps://vuldb.com/vuln/410953/cti
- www.dlink.comhttps://www.dlink.com/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-81433——
——0A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.6hCVE-2026-18145——
——0A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.6hCVE-2026-1023028.8 ALT—
——0Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)9hCVE-2026-7192——
——0A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/js/common/do_cmd.js’ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.9hCVE-2026-1008199.6 CRÍ—
——0Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.9hCVE-2026-1008148.8 ALT—
——0Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.9h