Executive brief
A security vulnerability has been identified in the D-Link DI-8003 router, a device typically used for managing internet connectivity in small to medium-sized environments. An attacker can exploit this flaw to crash the device or cause it to become unresponsive by sending a specially crafted web request. This could lead to a complete loss of internet access and network services for all connected users until the device is manually recovered.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the /xwgl_bwr.asp endpoint, which fails to properly validate the length of input provided to the 'name', 'qq', and 'time' parameters. An unauthenticated remote attacker can exploit this by sending a crafted HTTP GET request containing excessively long strings in these parameters. Successful exploitation results in a denial-of-service (DoS) condition, impacting the availability of the device. While the current assessment focuses on availability, buffer overflows can sometimes lead to remote code execution depending on the underlying architecture and memory protections.
Affected products
- D-Link DI-8003 firmware 16.07.26A1
Timeline
- 2026-04-08: advisory: Initial disclosure by MITRE/NVD