CVE-2025-50664: D-Link Di-8003 Firmware

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr.

Affected products

  • D-Link Di-8003 Firmware: version 16.07.26a1 only

Published 2026-04-08. Last modified 2026-07-25.