PT-2025-23875 · D Link · D-Link Dir-816

Pjqwudi

·

Published

2025-06-03

·

Updated

2025-07-01

·

CVE-2025-5623

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-816 version 1.10CNB05
Description A critical vulnerability was found in the D-Link DIR-816, affecting the qosClassifier function of the file /goform/qosClassifier. The manipulation of the dip address and sip address arguments leads to a stack-based buffer overflow. This issue can be exploited remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Recommendations As a temporary workaround, consider disabling the qosClassifier function until a patch is available. Restrict access to the /goform/qosClassifier endpoint to minimize the risk of exploitation. Avoid using the dip address and sip address parameters in the affected API endpoint until the issue is resolved. Replace unsupported devices and update immediately with the latest vendor release.

Exploit

Fix

Memory Corruption

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-06437
CVE-2025-5623

Affected Products

D-Link Dir-816