Executive brief
A security vulnerability exists in the D-Link DI-8003 router, a device used for managing network traffic. An attacker can exploit this flaw to cause the device to crash or become unresponsive, leading to a total loss of internet connectivity and network services. Because this product has reached its end-of-life status, no official security patches will be released, and the manufacturer recommends replacing the hardware.
Technical details
A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located within the /url_rule.asp endpoint due to improper validation of multiple parameters, including 'name', 'en', 'ips', 'u', 'time', 'act', 'rpri', and 'log'. An unauthenticated attacker can trigger the overflow by sending a crafted HTTP GET request containing overly long strings in these parameters. Successful exploitation leads to a denial-of-service (DoS) through a system crash. As the DI-8003 is an End-of-Life (EoL) product, D-Link has stated that no firmware updates will be provided to address this issue.
Affected products
- D-Link DI-8003 16.07.26A1
Timeline
- 2026-04-08: advisory: Initial disclosure by MITRE/NVD
- 2026-04-15: other: D-Link confirmed product is End-of-Life and will not receive patches