PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-45057 D‑Link CVE debrief

CVE-2025-45057 is a high-severity buffer overflow vulnerability in D-Link DI-8300 v16.07.26A1. The vulnerability is caused by a buffer overflow via the ip parameter in the ip_position_asp function, which allows attackers to cause a Denial of Service (DoS) via a crafted input. The CVSS score for this vulnerability is 7.5, indicating a high severity. The CVE record was published on 2026-04-08T18:24:45.597Z and was last modified on 2026-07-25T10:10:00.167Z.

Vendor
D‑Link
Product
DI-8300
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-25
Advisory published
2026-04-08
Advisory updated
2026-07-25

Who should care

Security teams and administrators responsible for managing D-Link DI-8300 devices should be aware of this vulnerability and take necessary steps to mitigate it. This vulnerability can be exploited by attackers to cause a Denial of Service (DoS), which can have significant impacts on the availability of affected systems.

Technical summary

The vulnerability is caused by a buffer overflow in the ip_position_asp function of D-Link DI-8300 v16.07.26A1. The function does not properly validate user input, allowing attackers to inject malicious data and cause a buffer overflow. This can lead to a Denial of Service (DoS) condition, making the affected system unavailable. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a high severity.

Defensive priority

High

Recommended defensive actions

  • Review and apply vendor patches or updates to address the vulnerability
  • Implement network segmentation to limit the spread of the vulnerability
  • Monitor system logs for suspicious activity
  • Conduct regular vulnerability assessments and penetration testing
  • Consider implementing compensating controls, such as intrusion detection and prevention systems

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, including its CVSS score and vector. The vendor advisory and product information are also available. However, the exact scope of affected systems and potential impact on the organization are not clear. Further investigation and risk assessment are necessary to determine the potential impact and prioritize mitigation efforts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T18:24:45.597Z and has not been modified since then.