CVE-2025-45058
7.5D-Link · DI-8300
A buffer overflow vulnerability in the D-Link DI-8300 router allows unauthenticated remote attackers to trigger a Denial of Service condition via the jingx_asp function.
Executive summary
A buffer overflow vulnerability in the D-Link DI-8300 router, identified as CVE-2025-45058, allows unauthenticated remote attackers to cause a system crash and Denial of Service.
Vulnerability
This vulnerability is a buffer overflow occurring within the jingx_asp function, triggered by sending malicious input to the fx parameter. The flaw is remotely exploitable by an unauthenticated attacker, as indicated by the CVSS vector AV:N/AC:L/PR:N.
Business impact
Successful exploitation of this vulnerability results in a Denial of Service, which effectively takes the affected networking equipment offline. With a CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, as it allows unauthorized parties to disrupt network services without requiring any prior authentication or user interaction.
Remediation
Immediate Action: Since a specific patch is not currently confirmed, administrators should restrict access to the device management interface to trusted IP addresses only and monitor for anomalous traffic patterns.
Proactive Monitoring: Security teams should review device system logs for unexpected reboots or crashes and monitor network traffic for abnormal spikes targeting the web interface.
Compensating Controls: Deploy a Web Application Firewall or network access control list to block unauthorized access to the affected device management parameters until a vendor firmware update is released.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the ease of exploitability and the potential for total loss of network connectivity, organizations should prioritize isolating affected D-Link DI-8300 units from the public internet. Monitor the official D-Link security bulletin portal for the release of firmware updates and apply them immediately upon availability to remediate the underlying buffer overflow.