CVE-2025-60554

9.8

D-Link · DIR600L

The D-Link DIR600L router contains a buffer overflow vulnerability in the formSetEnableWizard function, which can be triggered via the curTime parameter.

Executive summary

A critical, unauthenticated buffer overflow vulnerability in the D-Link DIR600L router allows remote attackers to potentially execute arbitrary code or cause a system crash.

Vulnerability

The flaw is a buffer overflow occurring within the formSetEnableWizard function. An unauthenticated attacker can supply a malicious payload through the curTime parameter to trigger the overflow, leading to potential remote code execution or denial of service.

Business impact

The CVSS score of 9.8 reflects the critical nature of this vulnerability, as it allows for full system compromise by an unauthenticated network-based attacker. Successful exploitation could result in a complete loss of confidentiality, integrity, and availability, potentially allowing attackers to gain persistent access to the network or disrupt critical business communication services.

Remediation

Immediate Action: As no patch is currently available, users should restrict access to the device management interface to trusted internal networks only. If possible, disable the device or replace it with a supported model that receives security updates.

Proactive Monitoring: Monitor network traffic for unusual or malformed HTTP requests directed at the router management interface, particularly those targeting the setup wizard endpoints.

Compensating Controls: Deploy a network-level firewall or Web Application Firewall (WAF) to block unauthorized access to the device management interface and inspect incoming traffic for buffer overflow patterns.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the technical write-up provided by the researcher on GitHub.

Analyst recommendation

Given the critical severity of this vulnerability and the existence of a public proof-of-concept, immediate defensive action is required. Organizations using the affected D-Link DIR600L hardware should isolate these devices from the public internet immediately to mitigate the risk of remote exploitation while awaiting further guidance or official patches from the vendor.

More D-Link CVEs

Sources