Junglewise Threat Intelligence

CVE-2025-50668: D-Link DI-8003 buffer overflow in /web_list_opt.asp

CVE-2025-50668 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A buffer overflow vulnerability exists in the D-Link DI-8003 enterprise router. This flaw allows an attacker to send specially crafted data to the device's web management interface, potentially causing the router to crash or become unresponsive. Such an exploit would disrupt network connectivity and business operations for all users relying on the affected hardware.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the '/web_list_opt.asp' endpoint and is triggered by improper length validation of the 's' parameter. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the device. According to the CVSS metrics, the primary impact is on availability (Denial of Service), though buffer overflows can sometimes lead to remote code execution depending on the underlying architecture and memory protections.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: advisory: Initial disclosure date

References

Related threats