CVE-2026-5981
8.8D-Link · DIR-605L
A buffer overflow vulnerability in the D-Link DIR-605L POST request handler allows remote attackers to trigger memory corruption via the curTime argument.
Executive summary
A remote buffer overflow vulnerability in D-Link DIR-605L devices poses a high risk of total system compromise, though official patches are unavailable as the product has reached end of life.
Vulnerability
The vulnerability exists within the formAdvFirewall function of the /goform/formAdvFirewall endpoint. An authenticated attacker can trigger a buffer overflow by sending a crafted POST request containing a malicious curTime argument, leading to memory corruption.
Business impact
Successful exploitation of this vulnerability results in total system compromise, potentially allowing an attacker to execute arbitrary code or cause a denial of service. With a CVSS score of 8.8, this flaw represents a significant risk to network integrity and confidentiality, particularly in environments where these legacy devices remain in operation.
Remediation
Immediate Action: As the vendor no longer supports this device, there is no official patch available; the most secure action is to decommission and replace the affected hardware immediately.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/formAdvFirewall endpoint and review system logs for signs of service crashes or unauthorized configuration changes.
Compensating Controls: Implement strict firewall rules to restrict access to the device management interface, ensuring it is not reachable from the public internet or untrusted network segments.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists as detailed in the referenced security researcher write-up.
Analyst recommendation
Given the lack of vendor support and the availability of a public proof-of-concept, the risk associated with this vulnerability is severe. Organizations currently utilizing D-Link DIR-605L devices are strongly advised to remove them from the network environment to prevent potential compromise, as no software update will be provided to mitigate this flaw.
More D-Link CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-356535 | D-Link DIR-605L POST Request formAdvFirewall buffer overflow Vulnerability database entry
- VDB-356535 | CTI Indicators (IOB, IOC, IOA)
- Submit #791854 | D-Link DIR-605L D-Link DIR-605L 2.13B01 BETA Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com