CVE-2025-6158
Last modified
CVE-2025-6158 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-655 Firmware | 1.00 |
References
- https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dir665-dlinkExploit, Third Party Advisory
- https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dir665-dlink#pocExploit, Third Party Advisory
- https://vuldb.com/?ctiid.312633Permissions Required, VDB Entry
- https://vuldb.com/?id.312633Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.593161Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6158?
How severe is CVE-2025-6158?
How do I fix CVE-2025-6158?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-61553An out-of-bounds write in VirtIO network device emulation in…8.2
- CVE-2025-61554A divide-by-zero in VirtIO network device emulation in BitVi…5.5
- CVE-2025-61557nixseparatedebuginfod before v0.4.1 is vulnerable to Directo…7.5
- CVE-2025-6156A vulnerability was found in PHPGurukul Nipah Virus Testing …8.8
- CVE-2025-6157A vulnerability was found in PHPGurukul Nipah Virus Testing …9.8
- CVE-2025-61577D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a st…7.5
- CVE-2025-61581** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expressi…7.5
- CVE-2025-61582TS3 Manager is modern web interface for maintaining Teamspea…7.5
- CVE-2025-61583TS3 Manager is modern web interface for maintaining Teamspea…6.1
- CVE-2025-61584serverless-dns is a RethinkDNS resolver that deploys to Clou…9.3
- CVE-2025-61585Rejected reason: Further research determined the issue is no…
- CVE-2025-61586FreshRSS is a free, self-hostable RSS aggregator. Versions 1…5.3
Are you affected by CVE-2025-6158?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
