Junglewise Threat Intelligence

CVE-2025-50666: D-Link DI-8003 buffer overflow in /web_post.asp

CVE-2025-50666 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8003 router that could allow an attacker to crash the device. By sending a specially crafted web request, an attacker can cause the system to become unresponsive, leading to a total loss of internet connectivity and network services. Because this product has reached its end-of-life status, the manufacturer will not be releasing a fix, and it is recommended that the hardware be replaced.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router, specifically within the firmware version 16.07.26A1. The vulnerability is located in the '/web_post.asp' endpoint due to improper length validation of multiple parameters, including 'name', 'en', 'user_id', 'log', and 'time'. An unauthenticated attacker can trigger this overflow by sending a crafted HTTP GET request containing excessively long strings in these parameters. Successful exploitation leads to a denial-of-service (DoS) condition. As the DI-8003 is an End-of-Life (EoL) product, D-Link has stated that no firmware updates will be provided to address this issue.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: disclosed: Initial disclosure of the vulnerability.
  • 2026-04-15: advisory: D-Link published a security announcement confirming the EoL status and lack of patches.

References

Related threats