CVE-2025-60572
7.5D-Link · DIR600L
A buffer overflow vulnerability exists in the D-Link DIR600L router within the formAdvNetwork function, which can be triggered via the curTime parameter.
Executive summary
The D-Link DIR600L router is vulnerable to a buffer overflow attack that can lead to a denial of service condition, posing a significant risk to network availability.
Vulnerability
This is a buffer overflow vulnerability located in the formAdvNetwork function. The flaw is triggered by sending a malformed curTime parameter, and the CVSS vector indicates that the attack can be performed by an unauthenticated remote user.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the affected network equipment unresponsive. With a CVSS score of 7.5, the vulnerability is classified as High, which suggests that the disruption of network services could significantly impact business operations and connectivity for downstream users.
Remediation
Immediate Action: Since no official patch is currently available, users should restrict access to the device management interface to trusted internal networks only.
Proactive Monitoring: Monitor network traffic for unusual payloads directed at the router management interface and observe the device for unexpected reboots or service outages.
Compensating Controls: Ensure that the router is not exposed directly to the public internet and utilize a firewall to block unauthorized access to administrative ports.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept is documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Given the High severity rating and the existence of a public proof-of-concept, users must treat this vulnerability with urgency. If firmware updates are not provided by the vendor, consider retiring the affected hardware or isolating it from all untrusted network segments to prevent potential service disruption.