Impact
The vulnerability is a stack-based buffer overflow caused by improper handling of the custom_error parameter in the /user.asp endpoint. An attacker could send a crafted HTTP request that overflows the stack, potentially allowing execution of arbitrary code on the device. This flaw threatens confidentiality, integrity, and availability of the device and any systems it serves.
Affected Systems
The affected product is the D-Link DI-8003 wireless router running firmware 16.07.26A1. The vulnerability is documented for this specific firmware version and is identifiable via the provided CPE entries for the device and its firmware.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity, while the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via the web interface, and requires only an unauthenticated HTTP request to /user.asp.
OpenCVE Enrichment