CVE-2025-4451
published 2025-05-09CVE-2025-4451: A vulnerability has been found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this vulnerability is the function formSetWAN_Wizard52. The…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.45%
82.5th percentile
A vulnerability has been found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this vulnerability is the function formSetWAN_Wizard52. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-619l | — | — |
| dlink | dir-619l_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qxp8-q6wp-7mq2: A vulnerability has been found in D-Link DIR-619L 2
ghsa_unreviewed·2025-05-09
CVE-2025-4451 [HIGH] CWE-119 GHSA-qxp8-q6wp-7mq2: A vulnerability has been found in D-Link DIR-619L 2
A vulnerability has been found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this vulnerability is the function formSetWAN_Wizard52. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
GHSA
Vyper Does Not Check the Success of Certain Precompile Calls
ghsa·2025-01-14
CVE-2025-21607 [LOW] CWE-670 Vyper Does Not Check the Success of Certain Precompile Calls
Vyper Does Not Check the Success of Certain Precompile Calls
### Summary
When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but let the overall execution continue. Then the execution result can be incorrect.
Based on EVM's rules, after the failed precompile the remaining code has only 1/64 of the pre-call-gas left (as 63/64 were forwarded and spent). Hence, only fairly simple executions can follow the failed precompile calls. Therefore, we found no significantly impacted real-world contracts.
The fix is tracked in https://github.com/vyperlang/vyper/pull/4451.
### Details
#### The relevant precompiles
##### EcRecover
E
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-38324 kernel: Linux kernel: Denial of Service in MPLS subsystem due to suspicious RCU usage
bugzilla·2025-07-10·CVSS 5.5
CVE-2025-38324 [MEDIUM] CVE-2025-38324 kernel: Linux kernel: Denial of Service in MPLS subsystem due to suspicious RCU usage
CVE-2025-38324 kernel: Linux kernel: Denial of Service in MPLS subsystem due to suspicious RCU usage
In the Linux kernel, the following vulnerability has been resolved:
mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
As syzbot reported [0], mpls_route_input_rcu() can be called
from mpls_getroute(), where is under RTNL.
net->mpls.platform_label is only updated under RTNL.
Let's use rcu_dereference_rtnl() in mpls_route_input_rcu() to
silence the splat.
[0]:
WARNING: suspicious RCU usage
6.15.0-rc7-syzkaller-00082-g5cdb2c77c4c3 #0 Not tainted
net/mpls/af_mpls.c:84 suspicious rcu_dereference_check() usage!
other info that might help us debug this:
rcu_scheduler_active = 2, debug_locks = 1
1 lock held by syz.2.4451/17730:
#0: ffffffff9012a3e8 (rtnl_mutex){+.+.}-{4:4}, at: rt
Bugzilla
CVE-2020-9850 webkitgtk: Logic issue may lead to arbitrary code execution
bugzilla·2020-09-16·CVSS 9.8
CVE-2020-9850 [CRITICAL] CVE-2020-9850 webkitgtk: Logic issue may lead to arbitrary code execution
CVE-2020-9850 webkitgtk: Logic issue may lead to arbitrary code execution
A logic issue was in webkitgtk. A remote attacker may be able to cause arbitrary code execution. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9850
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHSA-2025:10364 https://a
2025-05-09
Published