CVE-2025-60571
7.5D-Link · DIR600LAx
D-Link DIR600LAx firmware version FW116WWb01 contains a buffer overflow vulnerability in the formSetQoS function, which can be triggered via the curTime parameter.
Executive summary
A buffer overflow vulnerability in D-Link DIR600LAx firmware allows unauthenticated attackers to cause a denial of service condition on affected devices.
Vulnerability
This is a buffer overflow vulnerability residing within the formSetQoS function. An unauthenticated remote attacker can supply a specially crafted value to the curTime parameter to trigger the flaw, resulting in a system crash.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity due to the lack of required authentication. Successful exploitation leads to a denial of service, which can cause significant operational disruption for businesses or home users relying on the device for network connectivity. This could result in loss of productivity and require manual device reboots to restore service.
Remediation
Immediate Action: Since no official vendor patch is currently confirmed, administrators should restrict network access to the device management interface to trusted IP addresses only.
Proactive Monitoring: Monitor device uptime and system logs for unexpected reboots or service interruptions that may indicate an exploitation attempt.
Compensating Controls: Implement a firewall rule to block traffic to the vulnerable management function or place the device behind a robust gateway that filters malicious input.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the research write-up provided in the references.
Analyst recommendation
Given the high CVSS score and the presence of a public proof-of-concept, this vulnerability poses a credible risk to network availability. Users are strongly advised to limit exposure of the device interface to the public internet and verify if D-Link has released a firmware update that addresses this specific buffer overflow.