cbcvebase.
CVE-2025-8159
published 2025-07-25

CVE-2025-8159: A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLanguageChange of the file…

PriorityP277critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
14.28%
96.2th percentile
A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLanguageChange of the file /goform/formLanguageChange of the component HTTP POST Request Handler. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdir-513
dlinkdir-513_firmware

Detection & IOCsextracted from sources · hover to see the quote

url/goform/formLanguageChange
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link formLanguageChange currTime Parameter Buffer Overflow Attempt (CVE-2025-8159)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:26; content:"/goform/formLanguageChange"; fast_pattern; http.request_body; content:"currTime"; pcre:"/^[^,}$]{100,}(?:&|$)/R"; reference:url,github.com/boyslikesports/vul; reference:cve,2025-8159; classtype:web-application-attack; sid:2063756; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_07_25, cve CVE_2025_8159, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_07_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Match HTTP POST requests to the exact URI /goform/formLanguageChange (URI byte size must be exactly 26) containing 'currTime' in the request body with a value of 100 or more non-delimiter characters — indicative of a stack-based buffer overflow attempt.
  • Traffic is expected in plaintext (not TLS); deploy detection at the network perimeter and internally.
  • The exploit targets the formLanguageChange function via the curTime/currTime POST parameter, causing a stack-based buffer overflow in D-Link DIR-513 1.0.
  • ·This vulnerability only affects D-Link DIR-513 1.0, which is end-of-life and no longer supported by the vendor. No patch will be issued.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.