CVE-2025-60566

7.5

D-Link · DIR600L

A buffer overflow vulnerability exists in D-Link DIR600L firmware version Ax FW116WWb01, allowing remote attackers to trigger a denial of service via the curTime parameter.

Executive summary

The D-Link DIR600L router contains a buffer overflow vulnerability that allows unauthenticated attackers to cause a denial of service condition.

Vulnerability

The vulnerability is a buffer overflow occurring within the formSetMACFilter function when processing the curTime parameter. As indicated by the CVSS vector AV:N/AC:L/PR:N, this flaw can be triggered by an unauthenticated remote attacker.

Business impact

This vulnerability poses a significant risk to network availability. By successfully exploiting the buffer overflow, an attacker can crash the router, leading to a denial of service for all connected devices and services. With a CVSS score of 7.5, this high severity issue could disrupt critical business operations reliant on network connectivity.

Remediation

Immediate Action: Since no official patch is currently identified, isolate the affected device from the public internet and restrict access to the administrative interface to trusted management networks only.

Proactive Monitoring: Monitor device logs for unexpected reboots or crashes that may indicate an exploitation attempt.

Compensating Controls: Implement network segmentation and utilize a firewall to block untrusted external traffic from reaching the device management interface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.

Analyst recommendation

Given the public availability of a proof-of-concept and the potential for service disruption, organizations using the D-Link DIR600L should prioritize mitigating exposure. Users must ensure the device is not exposed to the public internet and should monitor vendor channels for the release of firmware updates to address this flaw permanently.

More D-Link CVEs

Sources