CVE-2025-60555

7.5

D-Link · DIR600L

A buffer overflow vulnerability exists in the D-Link DIR600L router within the curTime parameter of the formSetWizardSelectMode function.

Executive summary

A buffer overflow vulnerability in D-Link DIR600L routers allows unauthenticated attackers to cause a denial of service condition.

Vulnerability

This is a buffer overflow vulnerability triggered by sending malicious input to the curTime parameter within the formSetWizardSelectMode function. The CVSS vector indicates that the attack can be executed by an unauthenticated remote attacker with low complexity.

Business impact

The exploitation of this vulnerability leads to a denial of service, which can render the affected router unresponsive and disrupt network connectivity for all dependent users and services. With a CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, particularly in environments where these devices are used for critical connectivity.

Remediation

Immediate Action: Monitor official D-Link support channels for firmware updates and apply them as soon as they become available for the DIR600L series.

Proactive Monitoring: Review system logs and network traffic for unusual requests directed at the router management interface, particularly those targeting the wizard setup functions.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and ensure the web interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists per the technical write-up referenced in the CVE record.

Analyst recommendation

Given the potential for service disruption and the availability of a proof-of-concept, administrators should treat this vulnerability with high priority. If a firmware update is not currently available, ensure that the device management interface is firewalled from external access to mitigate the risk of unauthenticated exploitation.

More D-Link CVEs

Sources