Executive brief
A security vulnerability has been identified in the D-Link DI-8003 router, a device used for managing network traffic. An attacker can exploit this flaw to cause the device to crash or become unresponsive, leading to a total loss of internet connectivity for connected users. Because this product has reached its end-of-life status, the manufacturer will not be providing a security update, and it is recommended that the hardware be replaced.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located within the qj.asp endpoint and is caused by improper validation of user-supplied input lengths. An unauthenticated attacker can exploit this over the network by sending a specially crafted request to the affected endpoint. Successful exploitation results in a denial-of-service (DoS) condition. As the DI-8003 has reached End-of-Life (EoL) status, no official patch is expected; users are advised to retire the affected hardware.
Affected products
- D-Link DI-8003 16.07.26A1
Timeline
- 2026-04-08: advisory: Initial disclosure date
- 2026-04-15: other: Vendor confirmed End-of-Life status for affected hardware