D-Link DIR-600L A1 Buffer Overflow Vulnerability in WAN Wizard Function

Vulnerability

A buffer overflow vulnerability has been identified in the D-Link DIR-600L A1 router, specifically in the firmware version FW116WWb01. The issue arises in the function 'formSetWAN_Wizard7', where the 'curTime' parameter is processed. The vulnerability allows for arbitrary memory manipulation, which could potentially be exploited to execute arbitrary code or cause a denial-of-service condition.

Impact

Exploitation of this vulnerability leads to a buffer overflow, allowing for arbitrary memory manipulation. This could be used to execute arbitrary code or cause a denial-of-service condition by crashing the device.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the 'formSetWAN_Wizard7' function, including an overly long 'curTime' parameter. The 'sprintf' function used in this context does not validate the length of the input, causing the buffer overflow.

Added: Oct 24, 2025, 4:22 PM
Updated: Oct 24, 2025, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
10.0
exploitability
8.4
remediation
0.0
relevance
0.8
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.