Executive brief
A security vulnerability has been identified in the D-Link DI-8003 enterprise router. An attacker can exploit this flaw by sending a specially crafted web request to the device's management interface. If successful, this could cause the router to crash or become unresponsive, leading to a total loss of internet connectivity and network services for the organization.
Technical details
A stack-based buffer overflow (CWE-121) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located in the /xwgl_ref.asp endpoint due to improper validation of the length of several HTTP GET parameters, including 'name', 'en', 'user_id', 'shibie_name', 'time', 'act', 'log', and 'rpri'. A remote, unauthenticated attacker can exploit this by sending a crafted request containing excessively long strings in these parameters. Successful exploitation leads to a crash of the affected service, resulting in a denial-of-service (DoS) impact. While the reported impact is limited to availability, buffer overflows of this nature can sometimes be leveraged for remote code execution.
Affected products
- D-Link DI-8003 firmware 16.07.26A1
- D-Link DI-8003
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory