Junglewise Threat Intelligence

CVE-2025-50652: D-Link DI-8003 buffer overflow in /saveparm_usb.asp

CVE-2025-50652 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A vulnerability exists in the D-Link DI-8003 router, a device used for managing network traffic and internet connectivity. An attacker can exploit this flaw to cause the device to crash or become unresponsive, leading to a total loss of internet and network services for connected users. Because this product has reached its end-of-life status, the manufacturer will not be releasing a security patch, and it is recommended that the hardware be replaced.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located in the /saveparm_usb.asp endpoint and is triggered by improper handling of the 'id' parameter. A remote, unauthenticated attacker can send a specially crafted network request to this endpoint to overflow a buffer, leading to a denial-of-service (DoS) condition. As the DI-8003 is an End-of-Life (EoL) product, D-Link has stated that no further firmware updates will be developed to address this issue.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-15: advisory: Vendor confirmed EoL status and recommended replacement.

References

Related threats