Description
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.
Published: 2026-04-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow occurs when the device processes the "wans" parameter in the qos.asp web interface. The vulnerability can corrupt the program’s execution flow, allowing an attacker to inject and execute arbitrary code on the router. The weakness is a classic memory corruption flaw, and successful exploitation would give an attacker full control over the affected device, compromising confidentiality, integrity, and availability.

Affected Systems

Only the D‑Link DI‑8003 model running firmware version 16.07.26A1 is explicitly mentioned. No other firmware or model versions are listed in the advisory. Users with this exact build are affected.

Risk and Exploitability

The CVSS score is not provided in the data, so the exact severity cannot be quantified, but a classic buffer overflow is generally high risk. No EPSS score is available, indicating uncertainty about exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the web interface, where a crafted HTTP request to qos.asp could trigger the overflow, but this is inferred from the description.

Generated by OpenCVE AI on April 8, 2026 at 20:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version released by D‑Link

Generated by OpenCVE AI on April 8, 2026 at 20:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in D‑Link DI‑8003 WANS Parameter Leading to Potential Remote Code Execution
First Time appeared Dlink
Dlink di-8003
Weaknesses CWE-119
Vendors & Products Dlink
Dlink di-8003

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-08T17:24:49.470Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50647

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T19:24:15.460

Modified: 2026-04-08T21:26:13.410

Link: CVE-2025-50647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T20:13:01Z

Weaknesses