Junglewise Threat Intelligence

CVE-2025-50647: D-Link DI-8003 buffer overflow in qos.asp

CVE-2025-50647 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8003 enterprise router. This flaw allows a remote attacker to crash the device by sending specially crafted data to its management interface. Because this product has reached its end-of-life (EOL) status, D-Link will not be providing a security patch, and continued use of the device poses a risk to network availability.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 firmware version 16.07.26A1. The vulnerability is located in the qos.asp endpoint, which fails to properly validate the length of the 'wans' parameter before copying it into a fixed-size buffer. An unauthenticated attacker can exploit this over the network to trigger a crash, leading to a denial-of-service (DoS) state. As the DI-8003 is an End-of-Life (EOL) product, no official patches are expected; the vendor recommends retiring the affected hardware.

Affected products

  • D-Link DI-8003 16.07.26A1 and all hardware revisions

Timeline

  • 2026-04-08: disclosed: Initial disclosure date
  • 2026-04-15: advisory: Vendor advisory SAP10505 published confirming EOL status

References

Related threats