cbcvebase.

D-Link Di-8400 vulnerabilities

3 known vulnerabilities affecting d-link/di-8400.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3

Vulnerabilities

Page 1 of 1
CVE-2026-10206P2HIGHCVSS 8.8v16.07.26A12026-06-01
CVE-2026-10206 [HIGH] CWE-119 CVE-2026-10206: A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The initial researcher advisory mentions contradicting
nvd
CVE-2025-9938P2HIGHCVSS 8.8v16.07.26A12025-09-04
CVE-2025-9938 [HIGH] CWE-119 CVE-2025-9938: A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yy A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the file /yyxz.asp. This manipulation of the argument ID causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
nvd
CVE-2025-8175P3HIGHCVSS 7.5v16.07.26A12025-07-26
CVE-2025-8175 [HIGH] CWE-404 CVE-2025-8175: A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument share_enable leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may
nvd
D-Link Di-8400 vulnerabilities | cvebase