Executive brief
The D-Link DI-8300 enterprise router is affected by a security flaw that can allow an attacker to crash the device remotely. By sending a specially crafted network request, an attacker can trigger a system failure, leading to a total loss of internet connectivity and network services for the organization. This disruption can halt business operations and require a manual restart of the hardware to restore service.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8300 router firmware version 16.07.26A1. The vulnerability is located within the 'ip_position_asp' function, which fails to properly validate the length of the 'ip' parameter before copying it into a fixed-size buffer. An unauthenticated attacker can exploit this over the network by sending a crafted input to the affected component. Successful exploitation results in a crash of the device's management process or the entire system, leading to a Denial of Service (DoS) condition.
Affected products
- D-Link DI-8300 16.07.26A1
Timeline
- 2026-04-08: disclosed: Initial disclosure via MITRE/NVD
- 2026-04-08: advisory