Description
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch ASAP
AI Analysis

Impact

A buffer overflow occurs in the http_lanport parameter that is processed by the /webgl.asp endpoint on the D-Link DI-8003 device. The vulnerability arises from improper handling of input data, leading to a memory overwrite that could allow a malicious actor to execute arbitrary code. The impact is severe as it permits attackers to gain full control of the device and, if the device is a critical network gateway, to compromise the network it serves.

Affected Systems

The disclosed risk applies to D-Link DI-8003 routers running firmware version 16.07.26A1. No other product versions or variants are confirmed to be affected, but the issue may exist in other firmware releases that share the same code path.

Risk and Exploitability

No CVSS or EPSS metrics are provided, yet a buffer overflow indicates a high severity potential for exploitation. An attacker would need access to the router’s web interface, either from the local network or via a publicly exposed management console. The absence of a public exploit or patch does not reduce the inherent risk associated with memory corruption, so the vulnerability remains a critical threat if the device is exposed to untrusted traffic.

Generated by OpenCVE AI on April 8, 2026 at 19:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available firmware updates from D‑Link for the DI‑8003 router
  • Disable the web management interface if it is not required
  • Restrict access to the /webgl.asp endpoint to trusted local IP addresses
  • Monitor router logs for suspicious activity surrounding the http_lanport parameter

Generated by OpenCVE AI on April 8, 2026 at 19:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in D‑Link DI‑8003 via http_lanport Parameter
Weaknesses CWE-119

Wed, 08 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-08T17:50:21.854Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50673

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T19:24:18.040

Modified: 2026-04-08T21:26:13.410

Link: CVE-2025-50673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:45:01Z

Weaknesses