Dlink
Dlink Dir-605l Firmware: vulnerabilidades y CVE
Dlink Dir-605l Firmware tiene 65 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 8 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE65
Últimos 12 meses12
Críticas8
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-40655 | Alta (7.5) | 87% | ⚠ Explotación activa | 24 sept 2021 | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page |
| CVE-2014-8361 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 may 2015 | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42373 | Alta (8.8) | 0.98% | — | 4 may 2026 | D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password… |
| CVE-2026-42372 | Alta (8.8) | 0.47% | — | 4 may 2026 | D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password… |
| CVE-2026-5984 | Alta (7.4) | 1.2% | — | 9 abr 2026 | A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation of the argument curTime leads to… |
| CVE-2026-5983 | Alta (7.4) | 1.2% | — | 9 abr 2026 | A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing a manipulation of the argument… |
| CVE-2026-5982 | Alta (7.4) | 1.2% | — | 9 abr 2026 | A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the… |
| CVE-2026-5981 | Alta (7.4) | 1.2% | — | 9 abr 2026 | A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such manipulation of the argument curTime… |
| CVE-2026-5980 | Alta (7.4) | 1.2% | — | 9 abr 2026 | A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument… |
| CVE-2026-5979 | Alta (7.4) | 1.2% | — | 9 abr 2026 | A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the… |
| CVE-2026-2056 | Media (5.5) | 1.1% | — | 6 feb 2026 | A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of the component DHCP Connection Status… |
| CVE-2026-2055 | Media (5.5) | 1.1% | — | 6 feb 2026 | A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Client Information Handler. Executing a manipulation can lead to… |
| CVE-2026-2054 | Media (5.5) | 1.1% | — | 6 feb 2026 | A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Handler. Performing a manipulation results in information disclosure.… |
| CVE-2025-65731 | Media (6.8) | 0.43% | — | 8 ene 2026 | An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root… |
| CVE-2012-10021 | Crítica (9.3) | 4.4% | — | 31 jul 2025 | A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when… |
| CVE-2025-46176 | Media (6.5) | 0.37% | — | 23 may 2025 | Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis. |
| CVE-2025-4445 | Media (5.3) | 6.0% | — | 9 may 2025 | A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. The manipulation of the argument mac leads to command injection. It is possible to launch the… |
| CVE-2025-4443 | Media (5.3) | 59% | — | 9 may 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be… |
| CVE-2025-4442 | Alta (8.7) | 2.7% | — | 9 may 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetWAN_Wizard55. The manipulation of the argument curTime leads to buffer overflow. The… |
| CVE-2025-4441 | Alta (8.7) | 2.7% | — | 8 may 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formSetWAN_Wizard534. The manipulation of the argument curTime leads to buffer overflow. It is possible… |
| CVE-2025-2553 | Media (5.3) | 1.3% | — | 20 mar 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects some unknown processing of the file /goform/formVirtualServ. The manipulation leads to improper… |
| CVE-2025-2552 | Media (5.3) | 0.77% | — | 20 mar 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/formTcpipSetup. The manipulation leads to improper… |
| CVE-2025-2551 | Media (5.3) | 0.77% | — | 20 mar 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been classified as problematic. This affects an unknown part of the file /goform/formSetPortTr. The manipulation leads to improper access… |
| CVE-2025-2550 | Media (5.3) | 0.77% | — | 20 mar 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/formSetDDNS of the component DDNS Service. The… |
| CVE-2025-2549 | Media (5.3) | 1.0% | — | 20 mar 2025 | A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/formSetPassword. The manipulation… |
| CVE-2025-2548 | Media (5.3) | 1.0% | — | 20 mar 2025 | A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file /goform/formSetDomainFilter. The manipulation leads to improper… |
| CVE-2025-2547 | Media (5.3) | 0.77% | — | 20 mar 2025 | A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. This issue affects some unknown processing of the file /goform/formAdvNetwork. The manipulation leads to… |
| CVE-2025-2546 | Media (5.3) | 11% | — | 20 mar 2025 | A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The… |
| CVE-2024-11960 | Alta (8.7) | 1.8% | — | 28 nov 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime… |
| CVE-2024-11959 | Alta (8.7) | 1.8% | — | 28 nov 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime… |
| CVE-2024-9565 | Alta (8.7) | 2.0% | — | 7 oct 2024 | A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the… |
| CVE-2024-9564 | Alta (8.7) | 1.9% | — | 7 oct 2024 | A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.