Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2806 articles · 108988 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2025-50671
n/a · n/a

CVE-2025-50671: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_

Description

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time, act, log, and rpri.

Affected Products

VendorProductVersions
n/an/an/a

References

  • https://www.dlink.com/en/security-bulletin/
  • https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2025-50671 | D-Link DI-8003 16.07.26A1 Parameter /xwgl_ref.asp name/en/user_id/shibie_name/time/act/log/rpri buffer overflow
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedApr 8, 2026
Last enriched4h agov2
Trending Score20
Source articles1
Independent1
Info Completeness6/14
Missing: cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2023-46945EXP
CVE-2023-46945: QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
Trending: 49
HIGHCVE-2026-31040EXP
CVE-2026-31040: A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-fil
Trending: 45
HIGHCVE-2026-30080
CVE-2026-30080: OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported int
Trending: 27
NONECVE-2025-50663
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
Trending: 20
NONECVE-2025-50662
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.
Trending: 20

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 8, 2026
Discovered by ZDM
Apr 8, 2026
Updated: affectedVersions
Apr 8, 2026

Version History

v2
Last enriched 4h ago
v2Tier C4h ago

Updated vendor to D-Link, product to DI-8003, severity to CRITICAL, and added a detailed description of the vulnerability.

affectedVersions
via VulDB
v14h ago

Initial creation