Improper Access Control in D-Link Routers
CVE-2025-2551
Key Information:
Badges
What is CVE-2025-2551?
A vulnerability exists in D-Link’s DIR-618 and DIR-605L routers due to improper access control in the /goform/formSetPortTr file. Attackers with access to the local network could exploit this flaw, allowing unauthorized actions on the device. This issue affects older product versions that are no longer maintained, emphasizing the importance of updating or replacing unsupported devices to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DIR-605L 2.02
DIR-605L 3.02
DIR-618 2.02
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved