CVE-2025-60565

7.5

D-Link · DIR600L

D-Link DIR600L Ax firmware version FW116WWb01 contains a buffer overflow vulnerability in the formSchedule function, which can be triggered via the curTime parameter.

Executive summary

A buffer overflow vulnerability in the D-Link DIR600L router allows unauthenticated attackers to cause a denial of service condition.

Vulnerability

This is a buffer overflow vulnerability located in the formSchedule function, specifically reachable via the curTime parameter. The CVSS vector indicates that this flaw can be exploited by an unauthenticated attacker over the network with no user interaction required.

Business impact

Successful exploitation of this buffer overflow results in a denial of service, rendering the affected D-Link router unresponsive. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to network availability, potentially leading to business disruption if the device serves as a critical gateway or network component.

Remediation

Immediate Action: Monitor official D-Link support channels for firmware updates and apply them as soon as they become available.

Proactive Monitoring: Review network traffic and device logs for anomalous requests directed at the formSchedule function or unusual patterns in the curTime parameter.

Compensating Controls: Implement strict network access control lists to limit management interface access to trusted administrative IP addresses, thereby reducing the attack surface.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the referenced security researcher's write-up.

Analyst recommendation

Given the potential for denial of service and the existence of a public proof-of-concept, this vulnerability should be prioritized for mitigation. Organizations should restrict administrative access to the device management interface immediately while awaiting formal firmware patches from the vendor.

More D-Link CVEs

Sources