CVE-2025-60564
7.5D-Link · DIR600L
A buffer overflow vulnerability exists in the D-Link DIR600L router via the curTime parameter within the formSetLog function, potentially allowing for remote denial of service.
Executive summary
A buffer overflow vulnerability in D-Link DIR600L firmware version FW116WWb01 presents a significant risk of service disruption due to unauthenticated remote exploitation.
Vulnerability
This is a buffer overflow vulnerability triggered via the curTime parameter in the formSetLog function. The CVSS vector indicates that the attack is network-based and requires no authentication or user interaction.
Business impact
Successful exploitation of this buffer overflow could result in a denial of service, rendering the affected network device unresponsive. With a CVSS score of 7.5, this vulnerability is classified as High severity, posing a threat to operational continuity and network availability for organizations relying on this hardware.
Remediation
Immediate Action: Since no official patch is currently identified, verify if the vendor has released a firmware update or security advisory for the DIR600L and apply it immediately if available.
Proactive Monitoring: Monitor network traffic for anomalous requests directed at the device administration interface and review system logs for signs of unexpected crashes or service restarts.
Compensating Controls: Restrict access to the router management interface to trusted IP addresses only and ensure the device is not exposed directly to the public internet via a firewall or access control list.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical write-up provided in the research references.
Analyst recommendation
Given the high CVSS score and the existence of a public proof-of-concept, this vulnerability poses a credible threat to device availability. Administrators should prioritize isolating vulnerable units from external network exposure and monitor vendor channels for the release of a corrective firmware update.