ZeroHour

CVE-2025-4443

large

Remote command injection via sysCmd in D-Link DIR-605L 2.13B01 firmware

CVSS 4.0
5.3 medium
EPSS
57%p99
Published
()
Modified
AI analysis

CVE-2025-4443 is a command injection vulnerability in the function sub_454F2C of D-Link DIR-605L router firmware (build 2.13B01, classified under CWE-74/CWE-77). A remote attacker manipulates the 'sysCmd' argument of a request handled by this function to inject and execute arbitrary commands on the router; the CVSS 4.0 vector (AV:N/PR:L/UI:N) indicates a network vector requiring low privileges and no user interaction, with limited scored impacts on confidentiality, integrity and availability (VC:L/VI:L/VA:L), although the disclosure rates the issue as critical. Successful exploitation gives an attacker command execution on the device itself, which can serve as a foothold into the surrounding network. Only the DIR-605L is affected, and the source notes the flaw exists in a product that is no longer supported by D-Link (end-of-life); the vendor was contacted early about the disclosure. As of publication there is no known public proof-of-concept and the issue is not in CISA's KEV, but EPSS puts the probability of exploitation within 30 days at 56.8% (99th percentile), so exploitation attempts are considered likely.

What to do: Since the DIR-605L is end-of-life, no fixed firmware is confirmed in this disclosure — verify your current firmware build (2.13B01 is the referenced version) and check D-Link's support site for any final release before planning replacement. Until the router is retired, disable WAN-side remote management and UPnP and restrict the web management interface to trusted LAN clients. Given the 99th-percentile EPSS score, prioritize replacing or isolating these EOL devices rather than relying on a patch.

Affected
D-Link DIR-605L firmware2.13B01 (product is end-of-life; no other affected version ranges specified in the source data)
Estimated exposure
largeon the order of tens of thousands of legacy units still deployed (no official install-base figure published) — The DIR-605L was a mass-market consumer router sold globally for years and remains in service in home/SOHO deployments, and internet-wide scans of legacy D-Link DIR-series devices routinely surface devices in the tens of thousands,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.

Vendors
dlink
Products
dir-605l firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.