CVE-2025-61577

7.5

D-Link · DIR-816A2

A stack overflow vulnerability in the D-Link DIR-816A2 router allows unauthenticated remote attackers to trigger a Denial of Service condition via the statuscheckpppoeuser parameter.

Executive summary

A critical stack overflow vulnerability in the D-Link DIR-816A2 firmware exposes the device to remote Denial of Service attacks from unauthenticated actors.

Vulnerability

The vulnerability is a stack-based buffer overflow occurring within the dir_setWanWifi function. An unauthenticated attacker can supply a specially crafted input to the statuscheckpppoeuser parameter to crash the device service.

Business impact

The exploitation of this vulnerability results in a Denial of Service, which can render the affected D-Link networking hardware unresponsive. Given the CVSS score of 7.5, this poses a significant operational risk to organizations relying on these routers for connectivity, as it allows attackers to disrupt business continuity without requiring prior authentication.

Remediation

Immediate Action: Monitor official D-Link security bulletins for the release of a firmware patch and apply it immediately upon availability.

Proactive Monitoring: Review device access logs for unusual traffic patterns or malformed requests directed at administrative or status-checking parameters.

Compensating Controls: Restrict management access to the router interface to trusted internal IP addresses and implement network segmentation to prevent external exploitation.

Exploitation status

Public Exploit Available: Yes — technical write-ups and proof-of-concept details are available via the research references provided on GitHub (peris-navince and Flechao1 repositories).

Analyst recommendation

Organizations utilizing the D-Link DIR-816A2 model should prioritize this vulnerability due to the availability of public technical details and the ease of exploitation. While a patch is not yet confirmed, administrators must limit the attack surface by restricting network exposure of the device management interface until an official firmware update is deployed.

More D-Link CVEs

Sources