PT-2025-35854 · D Link · Di-8400

N0Ps1Ed

·

Published

2025-09-03

·

Updated

2025-09-05

·

CVE-2025-9938

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

D-Link DI-8400 version 16.07.26A1

Description:

A stack-based buffer overflow issue exists in the `yyxz dlink asp` function of the `/yyxz.asp` file. Manipulation of the `ID` argument can trigger this issue, allowing for remote exploitation. The exploit for this issue has been publicly released.

Recommendations:

As a temporary workaround, consider restricting access to the `/yyxz.asp` file until a fix is available.

Exploit

Fix

Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-9938

Affected Products

Di-8400