CVE-2026-5983
8.8D-Link · DIR-605L
A buffer overflow vulnerability in the D-Link DIR-605L formSetDDNS function allows remote attackers to trigger memory corruption via the curTime argument.
Executive summary
A critical buffer overflow vulnerability in the D-Link DIR-605L router, specifically within the formSetDDNS function, poses a significant risk of remote code execution.
Vulnerability
The vulnerability is a buffer overflow (CWE-120) occurring in the formSetDDNS function within the /goform/formSetDDNS endpoint. An authenticated attacker can trigger memory corruption by manipulating the curTime argument in a POST request.
Business impact
The exploitation of this buffer overflow could lead to unauthorized remote code execution, potentially resulting in full system compromise of the affected network device. Given the CVSS score of 8.8, this represents a high-severity risk that could facilitate lateral movement into the internal network or the interception of traffic. Because the product is no longer supported by the vendor, the lack of official security patches significantly increases the long-term operational risk.
Remediation
Immediate Action: As the affected product is end-of-life and no security update is available, the primary remediation is to decommission the device and replace it with a currently supported model.
Proactive Monitoring: Review network access logs for anomalous POST requests directed at the /goform/formSetDDNS endpoint and monitor for unexpected device reboots or instability which may indicate exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall or network intrusion detection system to filter or block malicious POST requests containing oversized payloads in the curTime parameter.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up provided by the researcher.
Analyst recommendation
Given the lack of vendor support for the DIR-605L, this vulnerability will remain unpatched indefinitely. Organizations currently utilizing this hardware must prioritize its replacement with a secure, vendor-supported alternative to mitigate the risk of remote compromise and persistent network threats.
More D-Link CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-356537 | D-Link DIR-605L POST Request formSetDDNS buffer overflow Vulnerability database entry
- VDB-356537 | CTI Indicators (IOB, IOC, IOA)
- Submit #791856 | D-Link DIR-605L D-Link DIR-605L 2.13B01 BETA Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com