Executive brief
A security vulnerability has been identified in the D-Link DI-8003 enterprise router. This flaw allows an attacker to send specially crafted data to the device's management interface, potentially causing the router to crash or become unresponsive. This could lead to a total loss of internet connectivity and network services for the business until the device is manually restarted or repaired.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router, specifically within firmware version 16.07.26A1. The vulnerability is located in the /wan_line_detection.asp endpoint due to improper validation of the 'iface' parameter. An unauthenticated attacker can exploit this over the network by sending a request with an oversized string to the affected parameter, leading to memory corruption. According to the CVSS metrics, the primary impact is on system availability (Denial of Service), though buffer overflows can sometimes lead to remote code execution. Users should check the D-Link security bulletin for firmware updates as this version is confirmed vulnerable.
Affected products
- D-Link DI-8003 16.07.26A1
Timeline
- 2026-04-08: disclosed: Initial NVD publication date
- 2026-04-08: advisory: CVE-2025-50667 assigned and published