CVE-2025-5623
published 2025-06-05CVE-2025-5623: A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file…
PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.73%
95.8th percentile
A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-816 | — | — |
| dlink | dir-816_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link qosClassifier Multiple Parameters Buffer Overflow Attempt (CVE-2025-5623)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:21; content:"/goform/qosClassifier"; fast_pattern; http.request_body; pcre:"/(?:d|s)ip\x5faddress\x3d[^&]{100,}(?:&|$)/"; reference:url,github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_51/51.md; reference:cve,2025-5623; classtype:web-application-attack; sid:2067141; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2026_01_27, cve CVE_2025_5623, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2026_01_27, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)- →Look for HTTP POST requests to the exact URI /goform/qosClassifier (URI length is exactly 21 bytes) targeting D-Link DIR-816 devices.
- →Detect oversized dip_address or sip_address parameter values in the POST body (100+ characters) as the overflow trigger for this vulnerability.
- →The exploit proof-of-concept is publicly available; reference the GitHub disclosure for payload patterns.
- →Traffic is expected in plaintext (not TLS); deploy detection at perimeter and internal network boundaries.
- →Map to MITRE ATT&CK: Initial Access (TA0001) via Exploit Public-Facing Application (T1190).
- ·This vulnerability only affects D-Link DIR-816 firmware version 1.10CNB05, which is end-of-life and no longer supported by the vendor; no official patch will be issued. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS D-Link qosClassifier Multiple Parameters Buffer Overflow Attempt (CVE-2025-5623)
suricata·2026-01-27·CVSS 9.3
CVE-2025-5623 [CRITICAL] ET WEB_SPECIFIC_APPS D-Link qosClassifier Multiple Parameters Buffer Overflow Attempt (CVE-2025-5623)
ET WEB_SPECIFIC_APPS D-Link qosClassifier Multiple Parameters Buffer Overflow Attempt (CVE-2025-5623)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link qosClassifier Multiple Parameters Buffer Overflow Attempt (CVE-2025-5623)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:21; content:"/goform/qosClassifier"; fast_pattern; http.request_body; pcre:"/(?:d|s)ip\x5faddress\x3d[^&]{100,}(?:&|$)/"; reference:url,github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_51/51.md; reference:cve,2025-5623; classtype:web-application-attack; sid:2067141; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2026_01_27, cve CVE_2025_5623, deployment Perimeter, deployment Internal, performance_impact Lo
No public exploits indexed.
2025-06-05
Published