CVE-2025-50671 is a buffer overflow vulnerability affecting D-Link DI-8003 firmware version 16.07.26A1 in the /xwgl_ref.asp endpoint. The flaw arises from improper parameter validation, allowing attackers to trigger memory corruption by submitting excessively long strings in multiple input fields including name, en, user_id, shibie_name, time, act, log, and rpri parameters. The vulnerability presents a HIGH severity risk with a CVSS 3.1 score of 7.5. It is remotely exploitable over the network without requiring authentication or user interaction, making the attack surface particularly broad. While the primary impact is denial of service through system crashes, the buffer overflow nature of the defect carries theoretical risk for code execution depending on memory protections in place. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and maintains an inactive status on threat tracking platforms. The extremely low EPSS probability score of 0.00174 indicates minimal community attention and limited exploit availability, suggesting this remains a lower-priority threat for immediate remediation compared to actively exploited vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.07.26a1CPE matchmatch criteria | cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.