CVE-2025-60562
7.5D-Link · DIR600L
The D-Link DIR600L router contains a buffer overflow vulnerability in the formWlSiteSurvey function, which can be triggered via the curTime parameter.
Executive summary
A buffer overflow vulnerability in the D-Link DIR600L router allows unauthenticated attackers to cause a denial of service condition.
Vulnerability
This is a buffer overflow vulnerability located in the formWlSiteSurvey function that is reachable via the curTime parameter. The CVSS vector of AV:N/AC:L/PR:N/UI:N indicates that this vulnerability is remotely exploitable by an unauthenticated attacker.
Business impact
The exploitation of this vulnerability results in a denial of service, which can disrupt network connectivity for all devices reliant on the affected router. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to operational continuity, potentially leading to productivity loss and the requirement for manual device reboots to restore service.
Remediation
Immediate Action: Since an official vendor patch is currently unknown, restrict management interface access to trusted IP addresses only and disable remote administration features until the manufacturer releases a firmware update.
Proactive Monitoring: Monitor device logs for unusual traffic patterns or repeated attempts to access the site survey configuration pages, which may indicate exploitation attempts.
Compensating Controls: Deploy a firewall policy to block unauthorized inbound requests to the router's management interface to prevent external attackers from reaching the vulnerable parameter.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the researcher write-up referenced in the CVE record.
Analyst recommendation
This vulnerability represents a high risk to network availability due to the lack of required authentication for exploitation. Administrators should treat the device as potentially compromised if exposed to the public internet and prioritize implementing network-level access controls while awaiting a formal firmware resolution from D-Link.