CVE-2026-5981

8.8

D-Link · DIR-605L

A buffer overflow vulnerability in the D-Link DIR-605L POST request handler allows remote attackers to trigger memory corruption via the curTime argument.

Executive summary

A remote buffer overflow vulnerability in D-Link DIR-605L devices poses a high risk of total system compromise, though official patches are unavailable as the product has reached end of life.

Vulnerability

The vulnerability exists within the formAdvFirewall function of the /goform/formAdvFirewall endpoint. An authenticated attacker can trigger a buffer overflow by sending a crafted POST request containing a malicious curTime argument, leading to memory corruption.

Business impact

Successful exploitation of this vulnerability results in total system compromise, potentially allowing an attacker to execute arbitrary code or cause a denial of service. With a CVSS score of 8.8, this flaw represents a significant risk to network integrity and confidentiality, particularly in environments where these legacy devices remain in operation.

Remediation

Immediate Action: As the vendor no longer supports this device, there is no official patch available; the most secure action is to decommission and replace the affected hardware immediately.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/formAdvFirewall endpoint and review system logs for signs of service crashes or unauthorized configuration changes.

Compensating Controls: Implement strict firewall rules to restrict access to the device management interface, ensuring it is not reachable from the public internet or untrusted network segments.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists as detailed in the referenced security researcher write-up.

Analyst recommendation

Given the lack of vendor support and the availability of a public proof-of-concept, the risk associated with this vulnerability is severe. Organizations currently utilizing D-Link DIR-605L devices are strongly advised to remove them from the network environment to prevent potential compromise, as no software update will be provided to mitigate this flaw.

More D-Link CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.