Executive brief
A security vulnerability has been identified in the D-Link DI-8003 router, a device used for managing network traffic and internet connectivity. An attacker can exploit this flaw to crash the device, leading to a complete loss of internet access and network services for all connected users. Because this product has reached its end-of-life status, the manufacturer will not be providing a security patch, and it is recommended that the hardware be replaced.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the /qos_type_asp.asp endpoint and is caused by insufficient validation of the 'name' input parameter. A remote, unauthenticated attacker can exploit this by sending a long string to the affected parameter, leading to memory corruption. According to the CVSS metrics provided by CISA-ADP, the primary impact is on system availability (Denial of Service), though the device has reached End-of-Life (EoL) status, meaning no official patches are expected.
Affected products
- D-Link DI-8003 firmware 16.07.26A1
- D-Link DI-8003 hardware All hardware revisions
Timeline
- 2026-04-08: disclosed: Initial disclosure date
- 2026-04-15: advisory: D-Link published EoL/EoS security announcement SAP10505