CVE-2025-60548
9.8D-Link · DIR600L
D-Link DIR600L firmware version Ax FW116WWb01 contains a buffer overflow vulnerability in the curTime parameter of the formLanSetupRouterSettings function.
Executive summary
A critical, unauthenticated buffer overflow vulnerability exists in D-Link DIR600L routers that allows for remote code execution.
Vulnerability
This is a buffer overflow vulnerability triggered via the curTime parameter within the formLanSetupRouterSettings function. The CVSS vector confirms that the flaw is remotely exploitable by an unauthenticated attacker with no user interaction required.
Business impact
Successful exploitation of this buffer overflow allows an attacker to execute arbitrary code on the affected router. This could result in a full system compromise, unauthorized access to network traffic, and potential pivot points into the internal local area network. Given the CVSS score of 9.8, the risk is classified as critical, necessitating immediate intervention to prevent total loss of device integrity.
Remediation
Immediate Action: As no official patch is currently listed, users should restrict administrative access to the device to trusted IP addresses only and disable remote management features. If the device is no longer supported by the vendor, decommissioning or replacing the hardware is the only reliable method to eliminate this risk.
Proactive Monitoring: Monitor network traffic for unusual patterns directed at router management interfaces and review system logs for signs of unauthorized configuration changes.
Compensating Controls: Implement a Web Application Firewall or network-level access control list to filter traffic reaching the router management interface, specifically blocking anomalous input to the curTime parameter.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept is available via the researcher's published technical write-up.
Analyst recommendation
This vulnerability presents a severe risk to network infrastructure due to the potential for unauthenticated remote code execution. Administrators must prioritize isolating these devices from the public internet immediately and seek alternative hardware if firmware updates remain unavailable from the vendor.