CVE-2025-50670: Buffer Overflow
Published Apr 8, 2026
·Updated
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwglbwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time parameters.
Affected Software
2 affected components
All of the following
Dlink Di-8003 Firmware=16.07.26a1
Dlink DI-8003
Event History
Apr 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:24 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50670?
The severity of CVE-2025-50670 is considered high due to the potential for remote code execution via buffer overflow.
2
How do I fix CVE-2025-50670?
To mitigate CVE-2025-50670, update the D-Link DI-8003 firmware to a version that addresses this vulnerability.
3
What is affected by CVE-2025-50670?
CVE-2025-50670 specifically affects the D-Link DI-8003 firmware version 16.07.26A1.
4
What type of vulnerability is CVE-2025-50670?
CVE-2025-50670 is a buffer overflow vulnerability that arises from improper parameter handling.
5
Can CVE-2025-50670 be exploited remotely?
Yes, CVE-2025-50670 can be exploited remotely through a crafted HTTP GET request.