D-Link Products Buffer Overflow Vulnerability in radius_asp Function Allowing Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in multiple D-Link router models, including the DI-8003, DI-8500, DI-8003G, DI-8200G, DI-8200, DI-8400, DI-8004w, DI-8100, and DI-8100G, all running specific firmware versions. The vulnerability arises in the radius_asp function, where attackers can exploit parameters such as rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip to trigger a stack-based buffer overflow. This exploitation leads to a denial-of-service condition, causing the device to become unresponsive.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, where the device becomes unresponsive. Additionally, according to a GitHub repository, this vulnerability could be leveraged for remote code execution.

Added: Apr 8, 2026, 6:46 PM
Updated: Apr 8, 2026, 6:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.4
remediation
0.0
relevance
5.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.