CVE-2026-94089: D-Link Dir-868l

Critical severity, CVSS 10.0. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

  • D-Link Dir-868l: version 2.01b05 only

Published 2026-09-20. Last modified 2026-09-22.