VulnerabilityAnalyzed
CVE-2025-4443
A vulnerability was found in D-Link DIR-605L 2.13B01.
MEDIUM 5.3EPSS 57.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 57.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 57.62% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-77
- Affected
- dlink/dir-605l firmware
- Source
- cna@vuldb.com
References
- https://github.com/jylsec/vuldb/blob/main/D-Link/dlink_dir605l/Command_injection-sub_454F2C-sysCmd/README.mdBroken Link
- https://vuldb.com/?ctiid.308051Permissions Required
- https://vuldb.com/?id.308051Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.558355Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.