Executive brief
A security vulnerability has been identified in the D-Link DI-8003 router, a device used for managing network connectivity. An attacker can exploit this flaw to cause the device to crash or become unresponsive, leading to a total loss of internet and network services for connected users. Because this product has reached its end-of-life status, the manufacturer will not be releasing a fix, and it is recommended that the hardware be replaced.
Technical details
A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located in the /thd_group.asp endpoint and is triggered by improper validation of the 'name' parameter. A remote, unauthenticated attacker can send a specially crafted HTTP request to overflow the buffer, leading to a crash of the web service or the entire device (Denial of Service). According to the vendor's advisory (SAP10505), this product is End-of-Life (EoL) and will not receive security updates; users are advised to retire the affected hardware.
Affected products
- D-Link DI-8003 16.07.26A1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-15: other: Vendor confirmed End-of-Life status and no planned patch