Junglewise Threat Intelligence

CVE-2025-50650: D-Link DI-8003 buffer overflow in /router.asp

CVE-2025-50650 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A buffer overflow vulnerability exists in the D-Link DI-8003 enterprise router. An attacker can exploit this flaw to crash the device, leading to a total loss of network connectivity and service availability. Because this product has reached its end-of-life (EOL) status, the manufacturer will not be releasing a security patch, and users are advised to replace the hardware.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router, specifically within the firmware version 16.07.26A1. The vulnerability is located in the /router.asp endpoint and is caused by inadequate validation of the input size for the 'routes_static' parameter. An unauthenticated attacker can send a specially crafted network request to trigger the overflow. Successful exploitation results in a denial-of-service (DoS) by crashing the device. D-Link has stated that this model is End-of-Life (EOL) and no patches will be provided; users are recommended to retire the affected devices.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: advisory: Initial disclosure by MITRE/NVD
  • 2026-04-15: other: D-Link confirmed EOL status and recommended device retirement

References

Related threats