Junglewise Threat Intelligence

CVE-2025-50672: D-Link DI-8003 buffer overflow in /yyxz_dlink.asp

CVE-2025-50672 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8003 enterprise router. The flaw exists in the device's web management interface and could allow an attacker to crash the device or cause it to become unresponsive. This would result in a loss of internet connectivity and network services for all connected users until the device is recovered.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the /yyxz_dlink.asp endpoint, where the application fails to properly validate the length of input parameters before copying them into memory buffers. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request to the affected endpoint. Successful exploitation can lead to a denial-of-service (DoS) condition, impacting the availability of the device. While the current CVSS assessment focuses on availability, buffer overflows can sometimes be leveraged for remote code execution depending on the underlying system architecture and protections.

Affected products

  • D-Link DI-8003 16.07.26A1

Timeline

  • 2026-04-08: advisory: Initial disclosure by MITRE/NVD

References

Related threats