CVE-2025-60564

7.5

D-Link · DIR600L

A buffer overflow vulnerability exists in the D-Link DIR600L router via the curTime parameter within the formSetLog function, potentially allowing for remote denial of service.

Executive summary

A buffer overflow vulnerability in D-Link DIR600L firmware version FW116WWb01 presents a significant risk of service disruption due to unauthenticated remote exploitation.

Vulnerability

This is a buffer overflow vulnerability triggered via the curTime parameter in the formSetLog function. The CVSS vector indicates that the attack is network-based and requires no authentication or user interaction.

Business impact

Successful exploitation of this buffer overflow could result in a denial of service, rendering the affected network device unresponsive. With a CVSS score of 7.5, this vulnerability is classified as High severity, posing a threat to operational continuity and network availability for organizations relying on this hardware.

Remediation

Immediate Action: Since no official patch is currently identified, verify if the vendor has released a firmware update or security advisory for the DIR600L and apply it immediately if available.

Proactive Monitoring: Monitor network traffic for anomalous requests directed at the device administration interface and review system logs for signs of unexpected crashes or service restarts.

Compensating Controls: Restrict access to the router management interface to trusted IP addresses only and ensure the device is not exposed directly to the public internet via a firewall or access control list.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical write-up provided in the research references.

Analyst recommendation

Given the high CVSS score and the existence of a public proof-of-concept, this vulnerability poses a credible threat to device availability. Administrators should prioritize isolating vulnerable units from external network exposure and monitor vendor channels for the release of a corrective firmware update.

More D-Link CVEs

Sources