D-Link DIR-600L Buffer Overflow Vulnerability in formWlSiteSurvey Function

Vulnerability

A critical buffer overflow vulnerability has been identified in the D-Link DIR-600L router, specifically in versions through 2.07B01. The issue arises in the formWlSiteSurvey function, where improper handling of the 'host' argument allows for remote exploitation. This vulnerability affects devices that are no longer supported by the manufacturer.

Impact

Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing a denial-of-service condition on the device.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the DIR-600L router's formWlSiteSurvey function, manipulating the 'host' argument to trigger the buffer overflow. This can be done remotely, without any authentication.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
7.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.