CVE-2025-60552
7.5D-Link · DIR600L
D-Link DIR600L firmware version FW116WWb01 contains a buffer overflow vulnerability in the formTcpipSetup function, which can be triggered via the curTime parameter.
Executive summary
A critical buffer overflow vulnerability in D-Link DIR600L firmware allows unauthenticated attackers to cause a denial of service condition on affected devices.
Vulnerability
The vulnerability is a buffer overflow occurring within the formTcpipSetup function, specifically triggered by the curTime parameter. Based on the CVSS vector (AV:N/AC:L/PR:N), this flaw is reachable by unauthenticated attackers over the network.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the network device unresponsive. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, as attackers could disrupt network connectivity for all users reliant on the affected D-Link infrastructure.
Remediation
Immediate Action: As no official vendor patch is currently confirmed, administrators should restrict network access to the device management interface to trusted internal IP addresses only.
Proactive Monitoring: Monitor system logs for frequent device reboots or unexpected service crashes, which may indicate exploitation attempts against the device firmware.
Compensating Controls: Implement strict network segmentation and ensure the device management interface is not exposed to the public internet, as this serves as a primary vector for unauthenticated access.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept is documented in the technical write-up referenced by the CVE record.
Analyst recommendation
The vulnerability presents a clear risk to device availability due to the lack of required authentication for exploitation. Security teams must prioritize isolating affected D-Link devices from external networks and monitor vendor support channels for the release of a firmware update to permanently remediate this buffer overflow.