Description
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
Published: 2026-04-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow occurs in the D‑Link DI‑8003 router when the web interface processes the pid parameter on the /trace.asp page. The flaw can lead to arbitrary code execution or denial of service on the device, as the overflow potentially allows an attacker to overwrite critical control data. The vulnerability is classified as CWE‑121, indicating a stack-based buffer overflow weakness.

Affected Systems

The affected system is the D‑Link DI‑8003 router running firmware version 16.07.26A1. No other firmware versions or hardware revisions are listed as impacted; the issue is tied specifically to the 16.07.26A1 build.

Risk and Exploitability

The CVSS score of 7.5 denotes a high severity, and the low EPSS score of less than 1% suggests that attacks have not yet been widely observed. The vulnerability does not appear in the CISA KEV catalog. Exploitation would likely occur over the local network or external web interface, requiring an adversary to send a specially crafted pid value to the /trace.asp endpoint. If successful, the attacker could compromise the router and potentially pivot to other devices on the same network.

Generated by OpenCVE AI on April 13, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that addresses the /trace.asp buffer overflow, as documented in the latest D‑Link security bulletin.
  • If an update is not available, disable or block access to the /trace.asp page through the device’s firewall or by restricting the web interface to a secure local network.
  • Limit administrative access to the router by using VPN or IP‑based restrictions and disable the web interface for remote users.
  • Monitor network traffic and device logs for suspicious requests to the /trace.asp endpoint and respond promptly to any anomalies.

Generated by OpenCVE AI on April 13, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 16:00:00 +0000


Tue, 14 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in /trace.asp Endpoint of D‑Link DI‑8003 16.07.26A1

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in D‑Link DI‑8003 trace.asp Endpoint
Weaknesses CWE-120
CWE-787

Fri, 10 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Dlink di-8003 Firmware
CPEs cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*
Vendors & Products Dlink di-8003 Firmware

Fri, 10 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in D‑Link DI‑8003 trace.asp Endpoint
First Time appeared Dlink
Dlink di-8003
Weaknesses CWE-120
CWE-787
Vendors & Products Dlink
Dlink di-8003

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
References

Subscriptions

Dlink Di-8003 Di-8003 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-22T15:36:13.137Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50657

cve-icon Vulnrichment

Updated: 2026-04-10T17:42:06.140Z

cve-icon NVD

Status : Modified

Published: 2026-04-08T19:24:16.363

Modified: 2026-04-22T16:16:50.580

Link: CVE-2025-50657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:40:30Z

Weaknesses