CVE-2025-6372: D-Link DIR-619L formSetWizard1 stack-based overflow
A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the file /goform/formSetWizard1. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6372?
CVE-2025-6372 is classified as a critical vulnerability.
How do I fix CVE-2025-6372?
To mitigate CVE-2025-6372, update the D-Link DIR-619L firmware to the latest version provided by D-Link.
What type of vulnerability is CVE-2025-6372?
CVE-2025-6372 is a stack-based buffer overflow vulnerability.
Which devices are affected by CVE-2025-6372?
CVE-2025-6372 affects the D-Link DIR-619L router running version 2.06B01.
What can be exploited in CVE-2025-6372?
The vulnerability can be exploited through manipulation of the curTime argument in the formSetWizard1 function.