CVE-2025-8184 is a critical stack-based buffer overflow vulnerability affecting D-Link DIR-513 routers up to firmware version 1.10. This flaw, found in the formSetWanL2TPcallback function, allows unauthenticated remote attackers to execute arbitrary code with maximum impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, a public exploit exists, and the vulnerability has garnered significant community discussion, indicating a high likelihood of exploitation. Affected devices are end-of-life and no longer supported, necessitating immediate replacement or isolation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0, <= 1.10CPE matchmatch criteria | cpe:2.3:o:dlink:dir-513_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.