Command Injection Vulnerability in D-Link DIR-605L Router
CVE-2025-4443

5.3MEDIUM

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
9 May 2025

Summary

A command injection vulnerability exists in the D-Link DIR-605L router (version 2.13B01), specifically within the function sub_454F2C. This vulnerability allows attackers to manipulate the sysCmd argument, enabling remote command execution. Given that this product is no longer supported by D-Link, users are strongly advised to consider transitioning to a supported device to safeguard their network against potential exploitation.

Affected Version(s)

DIR-605L 2.13B01

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jylsec (VulDB User)
.