CVE-2025-7945
8.8D-Link · DIR-513
A buffer overflow vulnerability exists in the D-Link DIR-513 router due to improper handling of the curTime argument within the formSetWanDhcpplus function.
Executive summary
A critical buffer overflow vulnerability in the D-Link DIR-513 router allows remote attackers to execute arbitrary code or cause system failure.
Vulnerability
This memory corruption flaw is triggered via the curTime argument in the formSetWanDhcpplus function. The vulnerability is exploitable by an authenticated user with low-level privileges, potentially leading to a complete compromise of the device.
Business impact
The exploitation of this vulnerability can lead to unauthorized remote code execution, resulting in a total compromise of the affected device. Given the CVSS score of 8.8, this represents a high risk to network integrity and confidentiality, particularly if the device serves as an entry point to internal segments. As the product is end-of-life, the risk of unpatched compromise is permanent.
Remediation
Immediate Action: Since the product is no longer supported by the vendor, the immediate action is to decommission the D-Link DIR-513 device from the network.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/formSetWanDhcpplus endpoint.
Compensating Controls: If immediate decommissioning is not possible, place the device behind a restricted firewall or VLAN to limit exposure to untrusted sources, and employ a WAF to inspect incoming traffic for malicious payloads.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up on GitHub.
Analyst recommendation
Because the D-Link DIR-513 is no longer receiving security updates, this vulnerability will remain present indefinitely. Security teams should prioritize the physical or logical removal of these devices from the production environment to eliminate the risk of exploitation. If the device must remain in service, restrict management interface access to trusted administrative networks only.
More D-Link CVEs
Sources
Originally found and disclosed by Yning (VulDB User), per the CVE Program record.
- VDB-317086 | D-Link DIR-513 formSetWanDhcpplus buffer overflow Vulnerability database entry
- VDB-317086 | CTI Indicators (IOB, IOC, IOA)
- Submit #619200 | D-Link DIR-513 10 Buffer Overflow Third-party advisory
- Related
- dlink.com