CVE-2025-7945 Details
Description
A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /goform/formSetWanDhcpplus. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
A critical buffer overflow vulnerability has been identified in the D-Link DIR-513 router, affecting versions through 20190831. The issue arises in the formSetWanDhcpplus function within the file /goform/formSetWanDhcpplus. The vulnerability is triggered by manipulating the curTime parameter, leading to a stack overflow. This flaw can be exploited remotely and may cause a denial-of-service condition, with the potential for further exploitation to gain shell access on the device.
No specific mitigation is known for this vulnerability. It is recommended to replace the affected device with an alternative product.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 22, 2025CISA-ADP
Assessed Jul 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/LYN1ng/D-linkdir513/blob/main/Dlink_DIR-513_Buffer_Overflow_Vulnerability.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?ctiid.317086 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.317086 | [email protected] | AdvisoryPartial Content |
| https://vuldb.com/?submit.619200 | [email protected] | ExploitTechnical Description |
| https://www.dlink.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| D-Link DIR-513 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2025 | New CVE Received | [email protected] |
Volerion