Executive brief
A security vulnerability has been identified in D-Link DI-8003 and DI-8003G enterprise routers. These devices are used to manage network traffic and provide internet connectivity for business environments. An attacker could exploit this flaw to crash the device, leading to a complete loss of internet and network services for all connected users.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 (firmware 16.07.26A1) and DI-8003G (firmware 19.12.10A1) routers. The vulnerability is located within the /wan_ping.asp endpoint due to improper validation of the 'wan_ping' parameter. A remote, unauthenticated attacker can send a specially crafted network request to trigger the overflow. According to the CVSS metrics, the primary impact is on system availability (Denial of Service), though buffer overflows can sometimes lead to remote code execution depending on the underlying architecture and protections. Users are advised to check the D-Link security bulletin for firmware updates.
Affected products
- D-Link DI-8003 16.07.26A1
- D-Link DI-8003G 19.12.10A1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory