Junglewise Threat Intelligence

CVE-2025-50645: D-Link DI-8003 buffer overflow in pppoe_list_opt.asp

CVE-2025-50645 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8003 router, a device used for managing network connections. An attacker can send a specially crafted request to the device to cause a system crash or service outage. Because this product has reached its End-of-Life (EOL) status, the manufacturer will not be releasing a fix, and it is recommended that the hardware be replaced.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located in the pppoe_list_opt.asp endpoint and is triggered by providing an excessively large value to the 's' parameter. This is a network-reachable attack that requires no authentication or user interaction. Successful exploitation allows an attacker to trigger a buffer overflow condition, leading to a denial-of-service (DoS). The manufacturer has stated that this device is End-of-Life (EOL) and no patches will be provided; users are advised to retire the affected hardware.

Affected products

  • D-Link DI-8003 16.07.26A1 and all hardware revisions

Timeline

  • 2026-04-08: disclosed: Initial disclosure via MITRE/NVD
  • 2026-04-15: advisory: D-Link published security announcement SAP10505 confirming EOL status

References

Related threats