CVE-2025-60563
7.5D-Link · DIR600L
A buffer overflow vulnerability exists in the D-Link DIR600L router within the formSetPortTr function, allowing for potential denial of service via the curTime parameter.
Executive summary
A buffer overflow vulnerability in the D-Link DIR600L router, specifically in the formSetPortTr function, presents a significant risk of service disruption to affected network devices.
Vulnerability
This is a buffer overflow vulnerability triggered via the curTime parameter in the formSetPortTr function. Based on the CVSS vector (AV:N/AC:L/PR:N), the attack is unauthenticated and requires no user interaction.
Business impact
The vulnerability poses a high risk to business continuity, as a successful exploit can lead to a denial of service condition, effectively taking the device offline. Given the CVSS score of 7.5, this flaw is categorized as high severity because it allows remote, unauthenticated attackers to disrupt network operations without requiring specialized access or privileges.
Remediation
Immediate Action: Since no official patch is currently available, restrict access to the device management interface to trusted internal networks only.
Proactive Monitoring: Monitor device logs for unusual traffic patterns or repeated crashes associated with the port triggering functions.
Compensating Controls: Implement firewall rules to block unsolicited inbound traffic directed at the router management interface from untrusted or public networks.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists, as documented in the researcher write-up referenced by the CVE record.
Analyst recommendation
Due to the remote and unauthenticated nature of this vulnerability, immediate defensive measures are required to protect network infrastructure. Because a vendor patch is currently unavailable, organizations must prioritize network segmentation and access control to mitigate the risk of remote service disruption until an official firmware update is provided by D-Link.