CVE-2025-60557

7.5

D-Link · DIR600L

A buffer overflow vulnerability exists in the D-Link DIR600L router within the formSetEasy_Wizard function, which can be triggered via the curTime parameter.

Executive summary

The D-Link DIR600L router is susceptible to a buffer overflow vulnerability that could allow an unauthenticated attacker to cause a denial of service.

Vulnerability

This is a buffer overflow vulnerability located in the formSetEasy_Wizard function. It is reachable via the curTime parameter and requires no authentication, allowing remote attackers to trigger a system crash.

Business impact

Successful exploitation of this buffer overflow results in a denial of service, effectively rendering the router unresponsive. Given the CVSS score of 7.5, this high severity flaw poses a risk to network availability, which could disrupt critical business operations reliant on this hardware for connectivity.

Remediation

Immediate Action: Contact the vendor or consult the official D-Link support portal for firmware updates addressing this specific buffer overflow.

Proactive Monitoring: Monitor device logs for unusual traffic patterns or service interruptions that may indicate attempts to crash the device.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and ensure the device is not exposed directly to the public internet.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the security researcher's write-up referenced by the CVE record.

Analyst recommendation

The vulnerability presents a credible risk to network stability due to the availability of a public proof-of-concept. Administrators should prioritize identifying vulnerable units within their environment and apply vendor-supplied patches as soon as they become available to prevent potential service disruption.

More D-Link CVEs

Sources