CVE-2025-45057
7.5D-Link · DI-8300
A buffer overflow vulnerability in the D-Link DI-8300 router allows unauthenticated attackers to cause a Denial of Service through a crafted ip parameter.
Executive summary
A buffer overflow vulnerability in the D-Link DI-8300 router allows unauthenticated attackers to trigger a device crash, resulting in a Denial of Service.
Vulnerability
This is a buffer overflow vulnerability located in the ip_position_asp function, triggered via the ip parameter. The vulnerability allows an unauthenticated, remote attacker to crash the device.
Business impact
The ability for an unauthenticated attacker to remotely crash the DI-8300 router creates a significant risk of service disruption for any network relying on this hardware. With a CVSS score of 7.5, this vulnerability is classified as High severity, as it directly impacts system availability and can be exploited without requiring valid user credentials.
Remediation
Immediate Action: Monitor official D-Link security bulletins for the release of a firmware patch and apply it to all affected devices immediately upon availability.
Proactive Monitoring: Review device access logs for unusual traffic patterns targeting the ip_position_asp function or frequent, unexplained system reboots.
Compensating Controls: If a patch is unavailable, restrict management interface access to trusted internal IP addresses and implement network-level filtering to block unauthorized access to the web administration interface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote, unauthenticated Denial of Service, organizations using the D-Link DI-8300 should prioritize securing the device management interface. Administrators must verify their current firmware version and prepare to deploy the vendor-supplied patch as soon as it is released to ensure network continuity and stability.