CVE-2025-70238

7.5

D-Link · DIR-513

A stack buffer overflow vulnerability exists in the D-Link DIR-513 v1.10 firmware via the curTime parameter to the goform/formSetWAN_Wizard52 endpoint, allowing for potential denial of service.

Executive summary

A critical stack buffer overflow vulnerability in D-Link DIR-513 routers allows unauthenticated attackers to trigger a denial of service condition.

Vulnerability

This is a stack buffer overflow vulnerability triggered by sending a specially crafted input to the curTime parameter within the goform/formSetWAN_Wizard52 function. The vulnerability is exploitable by unauthenticated attackers over the network.

Business impact

The potential for a denial of service attack against network infrastructure poses a significant risk to operational continuity. With a CVSS score of 7.5, this high severity vulnerability could lead to unplanned downtime and loss of network access for users reliant on the affected hardware.

Remediation

Immediate Action: Monitor vendor security bulletins for available firmware updates and apply them as soon as they are released.

Proactive Monitoring: Review device access logs for suspicious requests directed at the goform/formSetWAN_Wizard52 endpoint and monitor for unexpected device reboots.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and implement network segmentation to isolate the device from public internet exposure.

Exploitation status

Public Exploit Available: Yes, a proof of concept exists, as documented in the research repository hosted on GitHub.

Analyst recommendation

Given the exposure of the vulnerable endpoint to unauthenticated network access, immediate action is required to harden the environment. Administrators should verify their current firmware version and restrict management access until a vendor-supplied patch is available for deployment.

More D-Link CVEs

Sources