Junglewise Threat Intelligence

CVE-2025-50660: D-Link DI-8003 buffer overflow in /url_member.asp

CVE-2025-50660 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8003 enterprise router. This flaw allows an attacker to crash the device or cause it to become unresponsive by sending a specially crafted web request. Because this product has reached its end-of-life (EOL) status, the manufacturer will not be releasing a fix, and users are advised to replace the hardware to maintain network stability and security.

Technical details

A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the /url_member.asp endpoint and is triggered by improper validation of the 'name' parameter. An unauthenticated attacker can exploit this over the network by sending a crafted HTTP request with an overly long string in the affected parameter. Successful exploitation leads to a denial-of-service (DoS) condition. As the DI-8003 is an End-of-Life (EOL) product, no official patches are expected; D-Link recommends retiring the affected hardware.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory: Initial NVD publication
  • 2026-04-15: other: Vendor EOL announcement regarding the vulnerability

References

Related threats