Executive brief
A security vulnerability has been identified in the D-Link DI-8003 router, a device used for network connectivity. An attacker could exploit this flaw to cause the device to crash or become unresponsive, leading to a total loss of internet or network availability. Because this product has reached its end-of-life status, the manufacturer will not be releasing a fix, and users are advised to replace the hardware.
Technical details
A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the /usb_paswd.asp endpoint and is triggered by improper validation of the 'name' parameter. A remote, unauthenticated attacker can exploit this over the network by sending a specially crafted request. Successful exploitation results in a denial-of-service (DoS) condition, impacting the availability of the device. No patch is available as the product is End-of-Life (EoL).
Affected products
- D-Link DI-8003 firmware 16.07.26A1
- D-Link DI-8003 hardware All series
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-15: other: Vendor confirmed End-of-Life status and recommended replacement.