Junglewise Threat Intelligence

CVE-2025-50659: D-Link DI-8003 buffer overflow in /user.asp

CVE-2025-50659 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability exists in the D-Link DI-8003 enterprise router that could allow an attacker to crash the device. This router is used to manage network traffic and provide internet access for business environments. An exploit could lead to a total loss of network availability, disrupting operations and requiring a manual restart or replacement of the hardware.

Technical details

A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8003 router, specifically within the /user.asp endpoint. The vulnerability is caused by improper handling and insufficient bounds checking of the 'custom_error' parameter. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the affected endpoint. Successful exploitation results in a crash of the web service or the device itself, leading to a denial-of-service (DoS) state. The manufacturer has indicated this product is End-of-Life (EoL), and no official patch is expected.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: advisory: Initial disclosure of CVE-2025-50659
  • 2026-04-15: other: Vendor confirmed product is End-of-Life (EoL) and will not receive updates.

References

Related threats