CVE-2025-50671: D-Link Di-8003 Firmware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time, act, log, and rpri.
Affected products
- D-Link Di-8003 Firmware: version 16.07.26a1 only
Published 2026-04-08. Last modified 2026-07-25.