FormBook Malware – Active IOCs
April 21, 2025Multiple Cisco Products Vulnerabilities
April 21, 2025FormBook Malware – Active IOCs
April 21, 2025Multiple Cisco Products Vulnerabilities
April 21, 2025Severity
High
Analysis Summary
CVE-2025-3785
A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.49 is able to address this issue. It is recommended to upgrade the affected component.
Impact
- Buffer Overflow
Indicators of Compromise
CVE
CVE-2025-3785
Affected Vendors
- D-Link
Affected Products
- D-Link DWR-M961 1.1.36
Remediation
Refer to D-Link Website for patch, upgrade, or suggested workaround information.