Dlink Di-8400 Firmware vulnerabilities
4 known vulnerabilities affecting dlink/di-8400_firmware.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3
Vulnerabilities
Page 1 of 1
CVE-2025-9938HIGHCVSS 7.4v16.07.26a12025-09-04
CVE-2025-9938 [HIGH] CWE-119 CVE-2025-9938: A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yy
A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the file /yyxz.asp. This manipulation of the argument ID causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
nvd
CVE-2025-8175HIGHCVSS 7.1v16.07.26a12025-07-26
CVE-2025-8175 [HIGH] CWE-404 CVE-2025-8175: A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This
A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument share_enable leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may
nvd
CVE-2024-52739HIGHCVSS 8.0v16.07.26a12024-11-20
CVE-2024-52739 [HIGH] CWE-77 CVE-2024-52739: D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnera
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.
nvd
CVE-2024-44400CRITICALCVSS 9.8v16.07.26a12024-09-04
CVE-2024-44400 [CRITICAL] CWE-77 CVE-2024-44400: A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This is
A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
nvd