CVE-2026-5984

8.8

D-Link · DIR-605L

A buffer overflow vulnerability in the D-Link DIR-605L router allows remote attackers to trigger memory corruption via the formSetLog function.

Executive summary

A critical buffer overflow vulnerability in the D-Link DIR-605L router, version 2.13B01, poses a severe risk of remote code execution and total system compromise.

Vulnerability

The vulnerability exists within the formSetLog function, located at the /goform/formSetLog endpoint. An authenticated attacker can trigger a buffer overflow by manipulating the curTime argument in a crafted POST request.

Business impact

The exploitation of this memory corruption flaw can lead to a complete compromise of the affected router, potentially allowing an attacker to gain unauthorized control over network traffic. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk that could facilitate lateral movement within the network, data exfiltration, or total denial of service for critical infrastructure relying on this device.

Remediation

Immediate Action: Because the product is no longer supported by the manufacturer, there is no official security patch available. Organizations should immediately retire or replace this device with a supported, secure alternative.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/formSetLog path and look for unusual administrative activity or sudden device reboots.

Compensating Controls: Deploy a Web Application Firewall or network-based intrusion prevention system to filter and block malicious traffic targeting the vulnerable endpoint, though this should only be considered a temporary stopgap.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up referenced by the CVE record.

Analyst recommendation

The D-Link DIR-605L is currently end-of-life and lacks vendor support, meaning no patch will be provided for this critical flaw. Given the existence of a public proof-of-concept and the potential for total system compromise, immediate decommissioning of this hardware is strongly advised to maintain the security posture of the network environment.

More D-Link CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.