Junglewise Threat Intelligence

CVE-2025-50654: D-Link DI-8003 buffer overflow in /thd_member.asp

CVE-2025-50654 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8003 router, a device used for managing network traffic. An attacker can exploit this flaw to cause the device to crash or become unresponsive, leading to a total loss of internet connectivity for the office or home network. Because this product has reached its end-of-life status, the manufacturer will not be releasing a fix, and users are advised to replace the hardware.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located in the '/thd_member.asp' endpoint and is caused by improper validation of the 'id' parameter. An unauthenticated attacker can exploit this over the network by sending a malicious request that exceeds the expected buffer size, leading to memory corruption. According to the CVSS vector, the primary impact is on availability (Denial of Service). D-Link has classified this device as End-of-Life (EOL), meaning no official patches will be provided.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: disclosed: Initial disclosure of CVE-2025-50654
  • 2026-04-15: advisory: D-Link published security announcement SAP10505 confirming EOL status

References

Related threats