Junglewise Threat Intelligence

CVE-2025-45059: D-Link DI-8300 buffer overflow in tgfile_htm function

CVE-2025-45059 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Dlink Di-8300, Dlink Di-8300 Firmware. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DI-8300 enterprise router. This flaw allows an attacker to crash the device by sending a specially crafted request, leading to a complete loss of network connectivity for the business. This disruption can halt operations and prevent users from accessing critical online services until the device is manually recovered.

Technical details

A classic buffer overflow (CWE-120) exists in the D-Link DI-8300 router running firmware version 16.07.26A1. The vulnerability is located within the 'tgfile_htm' function and is triggered by providing an overly long string to the 'fn' parameter. An unauthenticated attacker can exploit this over the network to cause a memory corruption that results in a device crash or Denial of Service (DoS). While the current report focuses on availability impact, buffer overflows can sometimes be leveraged for remote code execution depending on the system architecture. No specific patch version was confirmed in the advisory, though users are encouraged to check D-Link's security bulletin for updates.

Affected products

  • D-Link DI-8300 16.07.26A1

Timeline

  • 2026-04-08: disclosed: Initial disclosure date
  • 2026-04-08: advisory: NVD publication date

References

Related threats