Junglewise Threat Intelligence

CVE-2025-50673: D-Link DI-8003 buffer overflow in /webgl.asp

CVE-2025-50673 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8003 Firmware, Dlink Di-8003. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8003 enterprise router. This flaw could allow an attacker to crash the device remotely, leading to a total loss of internet connectivity and network services for the business. The issue stems from how the router processes specific web-based configuration requests, potentially disrupting operations until the device is manually restarted or patched.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8003 router running firmware version 16.07.26A1. The vulnerability is located within the /webgl.asp endpoint and is triggered by improper length validation of the 'http_lanport' parameter. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request containing an overly long string in the affected parameter. Successful exploitation leads to memory corruption, typically resulting in a crash of the web management interface or the entire device (Denial of Service). While the current CVSS assessment focuses on availability, buffer overflows can sometimes be leveraged for remote code execution depending on the device's memory protections.

Affected products

  • D-Link DI-8003 firmware 16.07.26A1

Timeline

  • 2026-04-08: advisory: Initial NVD publication date
  • 2026-07-25: other: Last modified date in NVD record

References

Related threats