VulnerabilityAnalyzed
CVE-2025-14884
A vulnerability was detected in D-Link DIR-605 202WWB03.
HIGH 7.3EPSS 11.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Service. Performing manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
- CVSS 4.0
- 7.3 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 10.96% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-77
- Affected
- dlink/dir-605 firmware
- Source
- cna@vuldb.com
References
- https://tzh00203.notion.site/D-Link-DIR605-B1v202WWB03-Command-Injection-in-Firmware-Update-2cab5c52018a80de8df7f427ac2faf0e?source=copy_linkExploit, Third Party Advisory
- https://vuldb.com/?ctiid.337372Permissions Required, VDB Entry
- https://vuldb.com/?id.337372Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.715465Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.