CVE-2025-6369: D-Link DIR-619L formdumpeasysetup stack-based overflow
A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file /goform/formdumpeasysetup. The manipulation of the argument curTime/config.savenetworkenabled leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6369?
CVE-2025-6369 is classified as a critical vulnerability due to its potential for a stack-based buffer overflow.
How do I fix CVE-2025-6369?
To mitigate CVE-2025-6369, update the D-Link DIR-619L to the latest firmware version provided by D-Link.
What is affected by CVE-2025-6369?
CVE-2025-6369 affects the D-Link DIR-619L router model specifically.
What could be the impact of exploiting CVE-2025-6369?
Exploitation of CVE-2025-6369 could allow an attacker to execute arbitrary code on the affected system.
How does the exploit for CVE-2025-6369 work?
The exploit for CVE-2025-6369 works by manipulating specific arguments in the formdumpeasysetup function to trigger a buffer overflow.