cbcvebase.
CVE-2025-3785
published 2025-04-18

CVE-2025-3785: A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP…

PriorityP268high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
9.11%
94.7th percentile
A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.49 is able to address this issue. It is recommended to upgrade the affected component.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdwr-m961
dlinkdwr-m961_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/boafrm/formStaticDHCP
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link DWR-M961/Totolink N150RT formStaticDHCP buffer overflow (CVE-2025-3785, CVE-2025-3989)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:22; content:"/boafrm/formStaticDHCP"; fast_pattern; http.request_body; content:"hostname"; nocase; pcre:"/^.{200}/R"; reference:url,vulners.com/cvelist/CVELIST:CVE-2025-3785; reference:cve,2025-3785; reference:cve,2025-3989; classtype:attempted-admin; sid:2061744; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_04_18, cve CVE_2025_3785, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2025_04_18, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Look for HTTP POST requests to the exact URI /boafrm/formStaticDHCP (exact length 22 bytes) targeting D-Link DWR-M961 or Totolink N150RT devices.
  • Flag requests where the POST body contains a 'hostname' parameter value exceeding 200 characters, which is the overflow trigger condition.
  • The exploit is delivered over plaintext HTTP (not TLS), targeting networking equipment at the perimeter or internally.
  • The attack is remotely initiated and exploits the Authorization Interface component; classify as attempted-admin / Exploit_Public_Facing_Application (MITRE T1190, TA0001).
  • ·The Snort/Suricata rule (sid:2061744) also covers CVE-2025-3989 (Totolink N150RT) — detections firing on this rule may relate to either CVE; triage accordingly.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.