CVE-2025-60552

7.5

D-Link · DIR600L

D-Link DIR600L firmware version FW116WWb01 contains a buffer overflow vulnerability in the formTcpipSetup function, which can be triggered via the curTime parameter.

Executive summary

A critical buffer overflow vulnerability in D-Link DIR600L firmware allows unauthenticated attackers to cause a denial of service condition on affected devices.

Vulnerability

The vulnerability is a buffer overflow occurring within the formTcpipSetup function, specifically triggered by the curTime parameter. Based on the CVSS vector (AV:N/AC:L/PR:N), this flaw is reachable by unauthenticated attackers over the network.

Business impact

Successful exploitation of this vulnerability results in a denial of service, rendering the network device unresponsive. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, as attackers could disrupt network connectivity for all users reliant on the affected D-Link infrastructure.

Remediation

Immediate Action: As no official vendor patch is currently confirmed, administrators should restrict network access to the device management interface to trusted internal IP addresses only.

Proactive Monitoring: Monitor system logs for frequent device reboots or unexpected service crashes, which may indicate exploitation attempts against the device firmware.

Compensating Controls: Implement strict network segmentation and ensure the device management interface is not exposed to the public internet, as this serves as a primary vector for unauthenticated access.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept is documented in the technical write-up referenced by the CVE record.

Analyst recommendation

The vulnerability presents a clear risk to device availability due to the lack of required authentication for exploitation. Security teams must prioritize isolating affected D-Link devices from external networks and monitor vendor support channels for the release of a firmware update to permanently remediate this buffer overflow.

More D-Link CVEs

Sources