Junglewise Threat Intelligence

CVE-2025-45058: D-Link DI-8300 buffer overflow in jingx_asp function

CVE-2025-45058 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8300, Dlink Di-8300 Firmware. Vendors: Dlink, D-Link.

Executive brief

A vulnerability has been identified in the D-Link DI-8300 enterprise router. This flaw allows a remote attacker to crash the device by sending specially crafted data to a specific internal function. An exploit would result in a denial-of-service, disrupting internet connectivity and network operations for all connected users.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8300 router running firmware version 16.07.26A1. The vulnerability is located within the 'jingx_asp' function and is triggered by providing an oversized or malformed string to the 'fx' parameter. This is a network-reachable issue that does not require authentication or user interaction. Successful exploitation allows a remote attacker to cause a memory corruption that leads to a device crash or Denial of Service (DoS). While the current report focuses on DoS, buffer overflows of this nature can sometimes be leveraged for remote code execution.

Affected products

  • D-Link DI-8300 16.07.26A1

Timeline

  • 2026-04-08: disclosed: Initial disclosure date
  • 2026-04-08: advisory: NVD publication date

References

Related threats