Executive brief
A vulnerability has been identified in the D-Link DI-8300 enterprise router. This flaw allows a remote attacker to crash the device by sending specially crafted data to a specific internal function. An exploit would result in a denial-of-service, disrupting internet connectivity and network operations for all connected users.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link DI-8300 router running firmware version 16.07.26A1. The vulnerability is located within the 'jingx_asp' function and is triggered by providing an oversized or malformed string to the 'fx' parameter. This is a network-reachable issue that does not require authentication or user interaction. Successful exploitation allows a remote attacker to cause a memory corruption that leads to a device crash or Denial of Service (DoS). While the current report focuses on DoS, buffer overflows of this nature can sometimes be leveraged for remote code execution.
Affected products
- D-Link DI-8300 16.07.26A1
Timeline
- 2026-04-08: disclosed: Initial disclosure date
- 2026-04-08: advisory: NVD publication date