CVE-2025-2619

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 22, 2025
Updated: Mar 26, 2025
CWE ID 119
CWE ID 121
CWE ID 787

Summary

CVE-2025-2619 is a critical vulnerability affecting the D-Link DAP-1620 1.03 model. The issue lies within the check_dws_cookie function of the Cookie Handler component's /storage file, leading to a stack-based buffer overflow. An attacker can exploit this remotely, resulting in potential code execution. This vulnerability has been publicly disclosed, and it exclusively impacts outdated and unsupported D-Link devices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share