PT-2025-25551 · D Link · D-Link Dir-632

Xiaobor123

·

Published

2025-06-16

·

Updated

2025-06-17

·

CVE-2025-6121

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-632 version FW103B08
Description A critical issue has been found in the function get pure content of the component HTTP POST Request Handler. The manipulation of the argument Content-Length leads to a stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This issue only affects products that are no longer supported by the maintainer.
Recommendations As a temporary workaround, consider disabling the get pure content function until a patch is available. Restrict access to the HTTP POST Request Handler to minimize the risk of exploitation. Avoid using the Content-Length argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09539
CVE-2025-6121

Affected Products

D-Link Dir-632