cbcvebase.
CVE-2025-8184
published 2025-07-26

CVE-2025-8184: A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file…

PriorityP274critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.69%
94.5th percentile
A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Affected

12 ranges
VendorProductVersion rangeFixed in
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
d-linkdir-513
dlinkdir-513_firmware1.0 – 1.10

Detection & IOCsextracted from sources · hover to see the quote

url/goform/formSetWanL2TPtriggers
path/goform/formSetWan
othercurTime=<100+ char value>
  • Trigger on HTTP POST requests to URI paths beginning with /goform/formSetWan followed by L2TP, PPTP, or PPPoE suffixes (e.g., /goform/formSetWanL2TPtriggers). The overflow is delivered via the `curTime` POST body parameter with a value of 100 or more characters.
  • The exploit is plaintext (no TLS), making it detectable at the network perimeter or internally without SSL inspection. Deploy the Snort/Suricata rule (ET sid:2063869) at perimeter and internal chokepoints.
  • Public exploit code is available; reference the PoC repository at github.com/InfiniteLin/Lin-s-CVEdb for additional payload samples to build detection coverage.
  • The vulnerability is in the function formSetWanL2TPcallback. Monitor for stack-based buffer overflow crash indicators (device reboot/unresponsiveness) on D-Link DIR-513 devices running firmware up to 1.10 following POST requests to the affected endpoint.
  • ·This vulnerability only affects end-of-life hardware (D-Link DIR-513 up to firmware 1.10). No patch will be issued by the vendor; detection and network-level blocking are the only mitigations.
  • ·The Snort/Suricata rule (sid:2063869) covers three related CVEs (CVE-2025-8184, CVE-2025-8169, CVE-2025-8168) across multiple WAN form endpoints (L2TP, PPTP, PPPoE). Tune or split the rule if per-CVE attribution is required.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_oracle5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.