CVE-2025-8184
published 2025-07-26CVE-2025-8184: A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file…
PriorityP274critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.69%
94.5th percentile
A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| d-link | dir-513 | — | — |
| dlink | dir-513_firmware | 1.0 – 1.10 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger on HTTP POST requests to URI paths beginning with /goform/formSetWan followed by L2TP, PPTP, or PPPoE suffixes (e.g., /goform/formSetWanL2TPtriggers). The overflow is delivered via the `curTime` POST body parameter with a value of 100 or more characters.
- →The exploit is plaintext (no TLS), making it detectable at the network perimeter or internally without SSL inspection. Deploy the Snort/Suricata rule (ET sid:2063869) at perimeter and internal chokepoints.
- →Public exploit code is available; reference the PoC repository at github.com/InfiniteLin/Lin-s-CVEdb for additional payload samples to build detection coverage.
- →The vulnerability is in the function formSetWanL2TPcallback. Monitor for stack-based buffer overflow crash indicators (device reboot/unresponsiveness) on D-Link DIR-513 devices running firmware up to 1.10 following POST requests to the affected endpoint.
- ·This vulnerability only affects end-of-life hardware (D-Link DIR-513 up to firmware 1.10). No patch will be issued by the vendor; detection and network-level blocking are the only mitigations. ↗
- ·The Snort/Suricata rule (sid:2063869) covers three related CVEs (CVE-2025-8184, CVE-2025-8169, CVE-2025-8168) across multiple WAN form endpoints (L2TP, PPTP, PPPoE). Tune or split the rule if per-CVE attribution is required.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_oracle5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gcvq-jr65-5cwf: A vulnerability was found in D-Link DIR-513 up to 1
ghsa_unreviewed·2025-07-26
CVE-2025-8184 [HIGH] CWE-119 GHSA-gcvq-jr65-5cwf: A vulnerability was found in D-Link DIR-513 up to 1
A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security (Eclipse Jetty) — CVE-2024-8184
vendor_oracle·2025-07-15·CVSS 5.9
CVE-2024-8184 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Security (Eclipse Jetty) — CVE-2024-8184
Oracle Oracle Fusion Middleware Risk Matrix: Security (Eclipse Jetty) vulnerability
CVE: CVE-2024-8184
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Suricata
ET WEB_SPECIFIC_APPS D-Link formSetWAN Multiple Endpoints curTime Parameter Buffer Overflow Attempt (CVE-2025-8184, CVE-2025-8169, CVE,2025-8168)
suricata·2025-08-01·CVSS 7.4
CVE-2025-8168 [HIGH] ET WEB_SPECIFIC_APPS D-Link formSetWAN Multiple Endpoints curTime Parameter Buffer Overflow Attempt (CVE-2025-8184, CVE-2025-8169, CVE,2025-8168)
ET WEB_SPECIFIC_APPS D-Link formSetWAN Multiple Endpoints curTime Parameter Buffer Overflow Attempt (CVE-2025-8184, CVE-2025-8169, CVE,2025-8168)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link formSetWAN Multiple Endpoints curTime Parameter Buffer Overflow Attempt (CVE-2025-8184, CVE-2025-8169, CVE,2025-8168)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/goform/formSetWan"; fast_pattern; startswith; pcre:"/^(?:L2TP|PPTP|PPPoE)$/R"; http.request_body; content:"curTime|3d|"; pcre:"/^[^&]{100,}(?:&|$)/R"; reference:cve,2025-8168; reference:cve,2025-8184; reference:cve,2025-8169; reference:url,github.com/InfiniteLin/Lin-s-CVEdb; classtype:web-application-attack; sid:2063869; rev:1; metadata:affected_product D_Link, attack_target Ne
No public exploits indexed.
No writeups or analysis indexed.
2025-07-26
Published