VendorsD-Linkdi-8400_firmware16.07.26a1
Vulnerabilities

D-Link DI-8400 Firmware 16.07.26a1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-44400
A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
Published 2024-09-04 · Modified
9.8EPSS 0.145
CVE-2025-9938
D-Link DI-8400 yyxz.asp yyxz_dlink_asp stack-based overflow
Published 2025-09-03 · Analyzed
9.0EPSS 0.015
CVE-2024-52739
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.
Published 2024-11-20 · Analyzed
8.0EPSS 0.094
CVE-2025-8175
D-Link DI-8400 jhttpd usb_paswd.asp null pointer dereference
Published 2025-07-26 · Analyzed
7.5EPSS 0.016
CVE-2025-52222
D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2026-04-08 · Analyzed
7.5EPSS 0.003