cbcvebase.
CVE-2025-8168
published 2025-07-25

CVE-2025-8168: A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function websAspInit of the file…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.6th percentile
A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function websAspInit of the file /goform/formSetWanPPPoE. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdir-513
dlinkdir-513_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/goform/formSetWanPPPoE
commandcurTime=<100+ char payload>
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link formSetWAN Multiple Endpoints curTime Parameter Buffer Overflow Attempt (CVE-2025-8184, CVE-2025-8169, CVE,2025-8168)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/goform/formSetWan"; fast_pattern; startswith; pcre:"/^(?:L2TP|PPTP|PPPoE)$/R"; http.request_body; content:"curTime|3d|"; pcre:"/^[^&]{100,}(?:&|$)/R"; reference:cve,2025-8168; reference:cve,2025-8184; reference:cve,2025-8169; reference:url,github.com/InfiniteLin/Lin-s-CVEdb; classtype:web-application-attack; sid:2063869; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_08_01, cve CVE_2025_8184_CVE_2025_8169, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_08_01, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Detect HTTP POST requests to any /goform/formSetWan* endpoint (PPPoE, PPTP, L2TP variants) where the request body contains a 'curTime=' parameter value exceeding 100 characters — indicative of a buffer overflow attempt.
  • The attack is delivered via HTTP POST (plaintext, not TLS) targeting the device's web management interface; deploy detection at the network perimeter and internally.
  • The vulnerable function is websAspInit in /goform/formSetWanPPPoE; the manipulated argument is curTime, which triggers a stack/heap buffer overflow remotely without authentication.
  • Public exploit code is available in the researcher's CVE database on GitHub; treat any matching traffic as high-confidence exploitation.
  • ·The affected device (D-Link DIR-513 1.10) is end-of-life and will not receive patches; the only remediation is device replacement or network isolation.
  • ·The Snort/ET rule (sid:2063869) covers three related CVEs (CVE-2025-8168, CVE-2025-8169, CVE-2025-8184) across multiple WAN form endpoints; tune scope if only CVE-2025-8168 (/goform/formSetWanPPPoE) is in scope.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.