CVE-2025-60554
9.8D-Link · DIR600L
The D-Link DIR600L router contains a buffer overflow vulnerability in the formSetEnableWizard function, which can be triggered via the curTime parameter.
Executive summary
A critical, unauthenticated buffer overflow vulnerability in the D-Link DIR600L router allows remote attackers to potentially execute arbitrary code or cause a system crash.
Vulnerability
The flaw is a buffer overflow occurring within the formSetEnableWizard function. An unauthenticated attacker can supply a malicious payload through the curTime parameter to trigger the overflow, leading to potential remote code execution or denial of service.
Business impact
The CVSS score of 9.8 reflects the critical nature of this vulnerability, as it allows for full system compromise by an unauthenticated network-based attacker. Successful exploitation could result in a complete loss of confidentiality, integrity, and availability, potentially allowing attackers to gain persistent access to the network or disrupt critical business communication services.
Remediation
Immediate Action: As no patch is currently available, users should restrict access to the device management interface to trusted internal networks only. If possible, disable the device or replace it with a supported model that receives security updates.
Proactive Monitoring: Monitor network traffic for unusual or malformed HTTP requests directed at the router management interface, particularly those targeting the setup wizard endpoints.
Compensating Controls: Deploy a network-level firewall or Web Application Firewall (WAF) to block unauthorized access to the device management interface and inspect incoming traffic for buffer overflow patterns.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the technical write-up provided by the researcher on GitHub.
Analyst recommendation
Given the critical severity of this vulnerability and the existence of a public proof-of-concept, immediate defensive action is required. Organizations using the affected D-Link DIR600L hardware should isolate these devices from the public internet immediately to mitigate the risk of remote exploitation while awaiting further guidance or official patches from the vendor.