CVE-2026-94089

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

  • Published Sep 20, 2026
  • CVSS 9.3 critical
  • 1.0% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-94089 at the National Vulnerability Database