CVE-2026-5979

8.8

D-Link · DIR-605L

A buffer overflow vulnerability in the D-Link DIR-605L router allows remote attackers to trigger memory corruption via the formVirtualServ function.

Executive summary

A critical buffer overflow vulnerability in D-Link DIR-605L routers poses a severe risk of remote code execution, though exploitation requires low-level authentication.

Vulnerability

The vulnerability exists within the formVirtualServ function of the /goform/formVirtualServ endpoint, where improper handling of the curTime argument leads to a buffer overflow. This memory corruption flaw can be triggered remotely by an authenticated attacker with low-level privileges.

Business impact

The CVSS score of 8.8 reflects the high severity of this memory corruption flaw, which could lead to full system compromise or denial of service. Because the affected device is end-of-life and no longer supported, the risk of permanent vulnerability is high, potentially exposing internal network segments to unauthorized access and lateral movement.

Remediation

Immediate Action: As this product is no longer supported by the vendor, the immediate action is to retire the hardware and replace it with a currently supported device.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/formVirtualServ endpoint and review device logs for signs of abnormal crashes or unexpected reboots.

Compensating Controls: Deploy a network-level firewall or Web Application Firewall (WAF) to restrict access to the device management interface to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up referenced by the CVE record.

Analyst recommendation

Given that D-Link has officially ended support for the DIR-605L, no patch will be forthcoming. Organizations still utilizing this hardware must prioritize its decommissioning to mitigate the risk of remote exploitation. Continued use of this device in a production environment is strongly discouraged as it remains permanently susceptible to this buffer overflow flaw.

More D-Link CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.