Junglewise Threat Intelligence

CVE-2025-50653: D-Link DI-8003 buffer overflow in /time_group.asp

CVE-2025-50653 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A buffer overflow vulnerability exists in the D-Link DI-8003 enterprise router. This flaw allows a remote attacker to crash the device, leading to a complete loss of network connectivity and service availability. Because this product has reached its end-of-life (EOL) status, the manufacturer will not be releasing a security patch, and users are advised to replace the hardware.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located within the /time_group.asp endpoint due to improper length validation of the 'name' and 'mem' parameters. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the web management interface. Successful exploitation results in a crash of the affected service or device (Denial of Service). D-Link has stated that this model is End-of-Life (EOL) and no firmware updates will be provided to address this issue.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: disclosed: Initial disclosure of CVE-2025-50653
  • 2026-04-15: advisory: D-Link published security announcement SAP10505 confirming EOL status

References

Related threats