Executive brief
Multiple D-Link DI-series enterprise routers are affected by a security flaw that can be triggered remotely. By sending a specially crafted request to the device, an attacker can cause the router to crash or become unresponsive. This results in a total loss of network connectivity for all users and systems relying on the affected hardware.
Technical details
A classic buffer overflow (CWE-120) exists in the radius_asp function of several D-Link DI-series router models. The vulnerability is triggered by failing to properly validate the length of input provided to several parameters, including rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip. An unauthenticated remote attacker can exploit this by sending a crafted network request to the device's management interface. Successful exploitation results in a Denial of Service (DoS) condition, crashing the device and requiring a manual reboot to restore service. Affected firmware versions include v16.07.26A1, v17.12.21A1, and v17.12.20A1 depending on the specific hardware model.
Affected products
- D-Link DI-8003 v16.07.26A1
- D-Link DI-8500 v16.07.26A1
- D-Link DI-8003G v17.12.21A1
- D-Link DI-8200G v17.12.20A1
- D-Link DI-8200 v16.07.26A1
- D-Link DI-8400 v16.07.26A1
- D-Link DI-8004w v16.07.26A1
- D-Link DI-8100 v16.07.26A1
- D-Link DI-8100G v17.12.20A1
Timeline
- 2026-04-08: disclosed: Initial disclosure date
- 2026-04-08: advisory: NVD publication date