{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dir-868l-2.01b05/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:d_link:dir_868l:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-94089"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DIR-868L (2.01b05)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","network-security"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eD-Link DIR-868L version 2.01b05 is affected by a critical stack-based buffer overflow vulnerability (CVE-2026-94089) located within the Authentication Handler component. The flaw manifests in the strcpy function during the processing of the /webfa_authentication.cgi script. An unauthenticated remote attacker can exploit this by sending specially crafted input via the 'id' or 'password' HTTP POST parameters. Successful exploitation can lead to a crash or arbitrary code execution with the privileges of the web service. Given the public disclosure of the exploit and the ease of remote access, this vulnerability represents a significant risk to affected devices. Defenders should prioritize identifying and patching these legacy devices or isolating them from untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 10.0, indicating the highest level of severity. Successful exploitation allows for unauthenticated remote code execution, which could result in full device compromise, data theft, or integration of the device into a botnet. This threat is particularly relevant to small office and home office (SOHO) environments where this hardware is commonly deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all D-Link DIR-868L devices within the network environment.\u003c/li\u003e\n\u003cli\u003eBecause the device is legacy hardware, prioritize replacing affected units with currently supported models.\u003c/li\u003e\n\u003cli\u003eIf immediate replacement is not possible, apply network-level segmentation to restrict access to the web management interface of the affected devices to trusted administration subnets.\u003c/li\u003e\n\u003cli\u003eBlock external access to the /webfa_authentication.cgi endpoint on internet-facing edge routers.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-20T22:24:01Z","date_published":"2026-09-20T22:24:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dlink-buffer-overflow/","summary":"D-Link DIR-868L version 2.01b05 contains a critical stack-based buffer overflow vulnerability in the web authentication handler that allows unauthenticated remote code execution via malformed input.","title":"Remote Stack-based Buffer Overflow in D-Link DIR-868L","url":"https://feed.craftedsignal.io/briefs/2026-09-dlink-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - DIR-868L (2.01b05)","version":"https://jsonfeed.org/version/1.1"}