CVE-2026-5984
8.8D-Link · DIR-605L
A buffer overflow vulnerability in the D-Link DIR-605L router allows remote attackers to trigger memory corruption via the formSetLog function.
Executive summary
A critical buffer overflow vulnerability in the D-Link DIR-605L router, version 2.13B01, poses a severe risk of remote code execution and total system compromise.
Vulnerability
The vulnerability exists within the formSetLog function, located at the /goform/formSetLog endpoint. An authenticated attacker can trigger a buffer overflow by manipulating the curTime argument in a crafted POST request.
Business impact
The exploitation of this memory corruption flaw can lead to a complete compromise of the affected router, potentially allowing an attacker to gain unauthorized control over network traffic. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk that could facilitate lateral movement within the network, data exfiltration, or total denial of service for critical infrastructure relying on this device.
Remediation
Immediate Action: Because the product is no longer supported by the manufacturer, there is no official security patch available. Organizations should immediately retire or replace this device with a supported, secure alternative.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/formSetLog path and look for unusual administrative activity or sudden device reboots.
Compensating Controls: Deploy a Web Application Firewall or network-based intrusion prevention system to filter and block malicious traffic targeting the vulnerable endpoint, though this should only be considered a temporary stopgap.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up referenced by the CVE record.
Analyst recommendation
The D-Link DIR-605L is currently end-of-life and lacks vendor support, meaning no patch will be provided for this critical flaw. Given the existence of a public proof-of-concept and the potential for total system compromise, immediate decommissioning of this hardware is strongly advised to maintain the security posture of the network environment.
More D-Link CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-356538 | D-Link DIR-605L POST Request formSetLog buffer overflow Vulnerability database entry
- VDB-356538 | CTI Indicators (IOB, IOC, IOA)
- Submit #791857 | D-Link DIR-605L D-Link DIR-605L 2.13B01 BETA Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com