๐Ÿ” CVE Alert

CVE-2026-10206

HIGH 8.8

D-Link DI-8400 dbsrv.asp stack-based overflow

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The initial researcher advisory mentions contradicting parameter names to be affected.

CWE CWE-121 CWE-119
Vendor d-link
Product di-8400
Published Jun 1, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for d-link di-8400

Be the first to know when new high vulnerabilities affecting d-link di-8400 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

D-Link / DI-8400
16.07.26A1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/367486 vuldb.com: https://vuldb.com/vuln/367486/cti vuldb.com: https://vuldb.com/cve/CVE-2026-10206 vuldb.com: https://vuldb.com/submit/821716 github.com: https://github.com/666324/dlink-di8400-vuln/tree/main/dlink-di8400-vuln dlink.com: https://www.dlink.com/

Credits

๐Ÿ” Zheng (VulDB User)