Dlink Dir-600L Firmware vulnerabilities

34 known vulnerabilities affecting dlink/dir-600l_firmware.

Total CVEs
34
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH30

Vulnerabilities

Page 2 of 2
CVE-2025-60547HIGHCVSS 7.5v1.16wwb012025-10-24
CVE-2025-60547 [HIGH] CWE-121 CVE-2025-60547: D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter i D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.
nvd
CVE-2025-60568HIGHCVSS 7.5v1.16wwb012025-10-24
CVE-2025-60568 [HIGH] CWE-121 CVE-2025-60568: D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter i D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.
nvd
CVE-2025-60556HIGHCVSS 7.5v1.16wwb012025-10-24
CVE-2025-60556 [HIGH] CWE-121 CVE-2025-60556: D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter i D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizard1.
nvd
CVE-2025-60563HIGHCVSS 7.5v1.16wwb012025-10-24
CVE-2025-60563 [HIGH] CWE-121 CVE-2025-60563: D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter i D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.
nvd
CVE-2025-4342HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4342 [HIGH] CWE-119 CVE-2025-4342: A vulnerability, which was classified as critical, has been found in D-Link DIR-600L up to 2.07B01. A vulnerability, which was classified as critical, has been found in D-Link DIR-600L up to 2.07B01. Affected by this issue is the function formEasySetupWizard3. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4349HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4349 [HIGH] CWE-74 CVE-2025-4349: A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSysCmd. The manipulation of the argument host leads to command injection. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4343HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4343 [HIGH] CWE-119 CVE-2025-4343: A vulnerability has been found in D-Link DIR-600L up to 2.07B01 and classified as critical. This vul A vulnerability has been found in D-Link DIR-600L up to 2.07B01 and classified as critical. This vulnerability affects the function formEasySetupWizard. The manipulation of the argument host leads to buffer overflow. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4344HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4344 [HIGH] CWE-119 CVE-2025-4344: A vulnerability, which was classified as critical, was found in D-Link DIR-600L up to 2.07B01. This A vulnerability, which was classified as critical, was found in D-Link DIR-600L up to 2.07B01. This affects the function formLogin. The manipulation of the argument host leads to buffer overflow. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4350HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4350 [HIGH] CWE-74 CVE-2025-4350: A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerabilit A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulation of the argument host leads to command injection. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4348HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4348 [HIGH] CWE-119 CVE-2025-4348: A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been rated as critical. Affected A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been rated as critical. Affected by this issue is the function formSetWanL2TP. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4345HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4345 [HIGH] CWE-119 CVE-2025-4345: A vulnerability was found in D-Link DIR-600L up to 2.07B01 and classified as critical. This issue af A vulnerability was found in D-Link DIR-600L up to 2.07B01 and classified as critical. This issue affects the function formSetLog. The manipulation of the argument host leads to buffer overflow. The attack may be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4347HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4347 [HIGH] CWE-119 CVE-2025-4347: A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been declared as critical. Affect A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been declared as critical. Affected by this vulnerability is the function formWlSiteSurvey. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2025-4346HIGHCVSS 8.7≤ 2.07b012025-05-06
CVE-2025-4346 [HIGH] CWE-119 CVE-2025-4346: A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been classified as critical. Affe A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been classified as critical. Affected is the function formSetWAN_Wizard534. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2014-8361CRITICALCVSS 9.8KEVPoC≤ 1.15≤ 2.056b062015-05-01
CVE-2014-8361 [CRITICAL] CVE-2014-8361: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a craf The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
nvd