CVE-2025-60569
7.5D-Link · DIR600L
D-Link DIR600L devices contain a buffer overflow vulnerability in the formSetRoute function, reachable via the curTime parameter.
Executive summary
A critical buffer overflow vulnerability in the D-Link DIR600L router allows unauthenticated remote attackers to cause a denial of service condition.
Vulnerability
This vulnerability is a buffer overflow flaw within the formSetRoute function, triggered by the curTime parameter. Based on the CVSS vector, this is an unauthenticated vulnerability that does not require user interaction.
Business impact
Successful exploitation of this flaw allows an attacker to crash the affected network device, resulting in significant service disruption. Given the CVSS score of 7.5, this high-severity vulnerability poses a risk to business continuity for any organization relying on these routers for network connectivity.
Remediation
Immediate Action: Monitor the D-Link security bulletin portal for the release of a firmware update and apply it to all affected devices as soon as it becomes available.
Proactive Monitoring: Review device logs for unusual traffic patterns or repeated crashes associated with the administration interface or network configuration endpoints.
Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses only, and ensure the device is not exposed directly to the public internet.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up provided by the researcher.
Analyst recommendation
The presence of a public proof-of-concept for this unauthenticated denial of service vulnerability necessitates immediate defensive action. Administrators should verify the status of their firmware and prepare to patch immediately upon vendor release, while ensuring that device management interfaces are isolated from external access to minimize the attack surface.