Executive brief
A security vulnerability exists in the D-Link DI-8003 router, a device used for managing network traffic. An attacker can exploit this flaw to cause the device to crash or become unresponsive, leading to a total loss of internet connectivity for the office or home network. Because this product has reached its end-of-life status, the manufacturer will not be providing a security patch, and users are advised to replace the hardware.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router firmware version 16.07.26A1. The vulnerability is located in the /web_keyword.asp endpoint due to improper handling of input parameters. An unauthenticated remote attacker can trigger the overflow by sending a crafted HTTP GET request containing overly long strings in the 'name', 'en', 'time', 'mem_gb2312', or 'mem_utf8' parameters. Successful exploitation results in a denial-of-service (DoS) condition. As the DI-8003 is an End-of-Life (EoL) product, D-Link has stated that no firmware updates will be released to address this issue.
Affected products
- D-Link DI-8003 16.07.26A1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-15: other: Vendor confirmed EoL status and recommended replacement