CVE-2025-60549
7.5D-Link · DIR600L
A buffer overflow vulnerability exists in the D-Link DIR600L router via the curTime parameter in the formAutoDetecWAN_wizard4 function, allowing for potential denial of service.
Executive summary
The D-Link DIR600L router contains a buffer overflow vulnerability that could allow an unauthenticated attacker to cause a denial of service condition.
Vulnerability
The device is susceptible to a buffer overflow triggered by sending a specially crafted input to the curTime parameter within the formAutoDetecWAN_wizard4 function. This vulnerability is remotely exploitable by an unauthenticated attacker, as indicated by the CVSS attack vector.
Business impact
Successful exploitation of this vulnerability results in a denial of service, effectively taking the router offline and disrupting network connectivity for all connected users and services. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to operational continuity, especially for environments relying on these devices for gateway access.
Remediation
Immediate Action: Monitor official D-Link support channels for firmware updates that address this buffer overflow and apply them as soon as they become available.
Proactive Monitoring: Review system logs for signs of anomalous traffic or repeated service crashes directed at the administrative or configuration endpoints of the device.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and ensure the device is not exposed directly to the public internet via WAN.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Given the high CVSS score and the existence of a public proof-of-concept, this vulnerability should be prioritized for mitigation. Organizations currently utilizing the affected D-Link DIR600L routers should immediately restrict management access to mitigate exposure until a vendor-supplied firmware patch is released.