Contact Zero

CVE-2026-101081

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp o

score 15HIGH 8.5

Summary

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Published 2026-09-28 · first seen here 2026-10-10

Analysis & write-ups

No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.

Where it shows in your logs

Edge or network appliance (firewall, VPN, gateway) · Memory corruption (overflow, use-after-free) high confidence

Appliances usually run no EDR, so device logs, firewall flow logs and the vendor's integrity checker are often the only evidence. Get the logs off the box: attackers often wipe local logs.

What to look for

Data sources

Appliance system and admin logs · ATT&CK DS0015 Application Log Content

Sentinel
CommonSecurityLog (CEF from Fortinet, Palo Alto, Check Point, Cisco)Syslog
Splunk
Vendor add-ons: fortigate_event, pan:system, pan:config, cisco:asa, citrix:netscaler:syslog, f5:bigip:syslogChange.All_Changes
CrowdStrike
Falcon Next-Gen SIEM: third-party firewall / VPN connectors

Authentication and sessions · ATT&CK DS0028 Logon Session Creation / DS0002 User Account Authentication

Sentinel
SigninLogsSecurityEvent (4624, 4625, 4648)DeviceLogonEventsIdentityLogonEvents_Im_Authentication
Splunk
Authentication.Authenticationpan:globalprotectVPN sourcetypes
CrowdStrike
UserLogonUserLogonFailed2Falcon Identity Protection events

Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow

Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession
Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)
CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6

Process creation · ATT&CK DS0009 Process Creation

Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate
Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)
CrowdStrike
ProcessRollup2SyntheticProcessRollup2

A generic baseline worked out from the product type and weakness (CWE-119, CWE-121), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.

References