CVE-2025-60331
7.5D-Link · DIR-823G
A buffer overflow in the D-Link DIR-823G router allows unauthenticated remote attackers to trigger a denial of service condition.
Executive summary
A buffer overflow vulnerability in the D-Link DIR-823G router enables unauthenticated remote attackers to crash the device, resulting in a denial of service.
Vulnerability
The device contains a buffer overflow in the FillMacCloneMac parameter within the /EXCU_SHELL endpoint, which can be triggered by an unauthenticated attacker to cause a system crash.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a high potential for service disruption. Successful exploitation results in the unavailability of the network device, leading to potential business downtime, loss of connectivity for dependent services, and the requirement for manual intervention to restore device operations.
Remediation
Immediate Action: Consult the D-Link security bulletin portal for the latest firmware updates, as a vendor-supplied patch is currently unknown.
Proactive Monitoring: Monitor network gateway logs for suspicious traffic directed at the /EXCU_SHELL endpoint or anomalous patterns associated with the FillMacCloneMac parameter.
Compensating Controls: Implement perimeter firewall rules to restrict access to the management interface and common shell endpoints, ensuring they are not exposed to the public internet.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the GitHub repository referenced by the CVE record.
Analyst recommendation
Given the public availability of proof-of-concept code and the ease of triggering a denial of service, administrators should prioritize restricting network access to the affected hardware. Ensure the device is placed behind a robust firewall and monitor for vendor-provided firmware updates to permanently resolve the buffer overflow vulnerability.