Executive brief
A security vulnerability has been identified in the D-Link DI-8003 router that could allow an attacker to disrupt the device's operations. By sending specially crafted data to the router's management interface, an attacker can cause the system to crash or become unresponsive, leading to a loss of internet connectivity. This product has reached its end-of-life status, meaning the manufacturer will not be providing a security patch to fix this issue.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router, specifically within firmware version 16.07.26A1. The vulnerability is located in the /shut_set.asp endpoint and is caused by improper input validation of the 'vlan_name' parameter. A remote, unauthenticated attacker can exploit this by sending a crafted HTTP request with an overly long string in the affected parameter, leading to memory corruption. Successful exploitation results in a denial-of-service (DoS) condition. As the DI-8003 is an End-of-Life (EoL) product, D-Link has indicated that no firmware updates will be released to address this flaw.
Affected products
- D-Link DI-8003 16.07.26A1
Timeline
- 2026-04-08: disclosed: Initial disclosure date
- 2026-04-15: advisory: Vendor advisory published confirming EoL status