D Link · D-Link Dir-605L · CVE-2024-11959
Name of the Vulnerable Software and Affected Versions:
D-Link DIR-605L version 2.13B01
Description:
A critical issue affects the `formResetStatistic` function in the file `/goform/formResetStatistic`. The manipulation of the `curTime` argument leads to a buffer overflow. This can be initiated remotely. The exploit has been disclosed and may be used. It enables remote code execution on unsupported devices.
Recommendations:
For D-Link DIR-605L version 2.13B01, as a temporary workaround, consider disabling the `formResetStatistic` function until a patch is available. Restrict access to the `/goform/formResetStatistic` endpoint to minimize the risk of exploitation. Avoid using the `curTime` argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Isolate vulnerable routers and plan for replacement.