D-Link DIR-600L Buffer Overflow Vulnerability in formSetWanL2TP Function

Vulnerability

A critical buffer overflow vulnerability has been identified in the D-Link DIR-600L router, affecting versions prior to 2.07B01. The issue arises in the formSetWanL2TP function, where improper handling of the 'host' argument allows for memory corruption. This vulnerability can be exploited remotely, but it only impacts devices that are no longer supported by the manufacturer.

Impact

Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing a denial-of-service condition on the device.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
7.5
exploitability
4.9
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.