CVE-2025-60547

7.5

D-Link · DIR600L

A buffer overflow vulnerability exists in the D-Link DIR600L router within the curTime parameter of the formSetWAN_Wizard7 function, potentially allowing for service disruption.

Executive summary

The D-Link DIR600L router contains a buffer overflow vulnerability that could allow an unauthenticated attacker to trigger a denial of service condition.

Vulnerability

This is a buffer overflow vulnerability triggered via the curTime parameter in the formSetWAN_Wizard7 function. The CVSS vector indicates that this flaw can be exploited by an unauthenticated attacker over the network with low complexity.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which would render the affected networking device unresponsive. Given the CVSS score of 7.5, this high severity flaw poses a risk to operational continuity for any organization relying on this hardware for network connectivity or remote access.

Remediation

Immediate Action: Check the official D-Link support portal for firmware updates addressing the formSetWAN_Wizard7 buffer overflow and apply them immediately.

Proactive Monitoring: Monitor network traffic for unusual payloads targeting the device management interface and inspect system logs for service crashes or unexpected reboots.

Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses only and disable remote management features where possible to reduce the attack surface.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the referenced researcher write-up.

Analyst recommendation

Due to the unauthenticated nature of this vulnerability and the potential for a denial of service, users should prioritize the identification of current firmware versions. If a patch is not yet available from the vendor, immediate network segmentation or disabling of remote management interfaces is strongly advised to prevent exploitation until a firmware update is applied.

More D-Link CVEs

Sources