Description
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote code execution via buffer overflow
Action: Patch
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow caused by improper handling of parameters in the /yyxz_dlink.asp endpoint of the D‑Link DI‑8003 router. An attacker able to trigger the overflow may inject malicious code or cause a crash, leading to control over the device or denial of service. This weakness allows an attacker to compromise confidentiality, integrity, and availability of the firmware influencing all traffic passing through the router.

Affected Systems

Only the D‑Link DI‑8003 router running firmware version 16.07.26A1 is reported as affected. No other vendors, products, or firmware revisions are listed.

Risk and Exploitability

The CVE is not included in the CISA KEV database and no EPSS score is available, yet the nature of the flaw is known to allow remote code execution. The attack requires network access to the device’s web interface, specifically the /yyxz_dlink.asp page, and may require crafting of a carefully constructed request. Without a publicly available exploit, the likelihood of real‑world attacks is uncertain, but given the severity of buffer overflows, the risk to any organization running the vulnerable firmware remains significant.

Generated by OpenCVE AI on April 8, 2026 at 19:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from D‑Link for the DI‑8003 router

Generated by OpenCVE AI on April 8, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in D‑Link DI‑8003 Router via /yyxz_dlink.asp
First Time appeared Dlink
Dlink di-8003
Weaknesses CWE-120
Vendors & Products Dlink
Dlink di-8003

Wed, 08 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-08T17:49:41.514Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50672

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T19:24:17.913

Modified: 2026-04-08T21:26:13.410

Link: CVE-2025-50672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:45:03Z

Weaknesses