Executive brief
A security vulnerability has been identified in the D-Link DI-8003 enterprise router, a device used to manage network traffic and provide internet connectivity. An attacker can exploit this flaw to crash the device, leading to a complete loss of internet and network services for the organization. Because this product has reached its end-of-life status, the manufacturer will not be releasing a fix, and it is recommended that the hardware be replaced.
Technical details
A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the '/url_group.asp' endpoint and is triggered by improper validation of the 'name' parameter. A remote, unauthenticated attacker can exploit this by sending a specially crafted network request to the device. Successful exploitation results in a Denial of Service (DoS) condition. As the DI-8003 is an End-of-Life (EoL) product, D-Link has stated that no firmware updates will be provided to address this issue.
Affected products
- D-Link DI-8003 16.07.26A1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory: NVD publication date
- 2026-04-15: other: Vendor acknowledgment of EoL status