CVE-2026-5980

8.8

D-Link · DIR-605L

A buffer overflow vulnerability exists in the D-Link DIR-605L router due to improper handling of the curTime argument in the formSetMACFilter function.

Executive summary

A remote buffer overflow vulnerability in D-Link DIR-605L version 2.13B01 poses a critical risk of total system compromise as the device has reached end-of-life status.

Vulnerability

This vulnerability is a buffer overflow (CWE-120) triggered by sending a crafted POST request to the /goform/formSetMACFilter endpoint. The attack requires low-level privileges (authenticated user) to manipulate the curTime parameter, potentially leading to arbitrary code execution.

Business impact

The exploitation of this vulnerability allows an attacker to achieve total system compromise, potentially leading to unauthorized network access, data exfiltration, or complete loss of router availability. Given the CVSS score of 8.8, this flaw represents a high-severity risk. Because the product is no longer supported by the vendor, there will be no official security patches, which significantly increases the long-term operational risk to the environment.

Remediation

Immediate Action: Since this device is end-of-life and no patch will be provided, immediately decommission and replace the affected D-Link DIR-605L hardware with a currently supported model.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/formSetMACFilter endpoint and review device logs for signs of unauthorized configuration changes or unexpected reboots.

Compensating Controls: If the device cannot be immediately retired, place it behind an isolated network segment and implement strict access control lists to limit administrative access to only known, trusted internal IP addresses.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up provided by the researcher.

Analyst recommendation

The severity of this vulnerability, combined with the fact that D-Link no longer provides security updates for the DIR-605L, necessitates an immediate transition away from this hardware. Organizations must prioritize the replacement of these devices to maintain a secure network perimeter, as they are now inherently vulnerable to remote exploitation without any path to remediation.

More D-Link CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.