← All Advisories

D-Link DI-8003 buffer overflow in url_rule.asp via multiple URL policy parameters causes denial of service

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2025-50661

Key Details

CVECVE-2025-50661
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsdlink di-8003_firmware
Classified asCWE-121 (Stack-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dlinkdi-8003_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, en, ips, u, time, act, rpri, and log. (NVD)

What to Do

Monitor dlink's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-50661
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-50661
Vendor advisoryhttps://www.dlink.com/en/security-bulletin/