PT-2025-53654 · D Link · Dir-600M

Lontan0

·

Published

2025-12-25

·

Updated

2026-01-08

·

CVE-2025-15194

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-600 versions prior to 2.15WWb02
Description A stack-based buffer overflow exists in the HTTP Header Handler component of D-Link DIR-600. The issue is due to the manipulation of the Cookie argument within the hedwig.cgi file. This allows for remote exploitation. The exploit has been made public. This vulnerability affects products that are no longer supported by the maintainer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-16479
CVE-2025-15194

Affected Products

Dir-600M