Dlink
Dlink Dir-605l Firmware: vulnerabilities and CVEs
Dlink Dir-605l Firmware has 65 published vulnerabilities, 12 of them in the last 12 months. 8 are rated critical and 2 are listed by CISA as actively exploited.
CVEs65
Last 12 months12
Critical8
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40655 | High (7.5) | 87% | ⚠ Active exploitation | Sep 24, 2021 | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page |
| CVE-2014-8361 | Critical (9.8) | 100% | ⚠ Active exploitation | May 1, 2015 | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42373 | High (8.8) | 0.98% | — | May 4, 2026 | D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password… |
| CVE-2026-42372 | High (8.8) | 0.47% | — | May 4, 2026 | D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password… |
| CVE-2026-5984 | High (7.4) | 1.2% | — | Apr 9, 2026 | A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation of the argument curTime leads to… |
| CVE-2026-5983 | High (7.4) | 1.2% | — | Apr 9, 2026 | A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing a manipulation of the argument… |
| CVE-2026-5982 | High (7.4) | 1.2% | — | Apr 9, 2026 | A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the… |
| CVE-2026-5981 | High (7.4) | 1.2% | — | Apr 9, 2026 | A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such manipulation of the argument curTime… |
| CVE-2026-5980 | High (7.4) | 1.2% | — | Apr 9, 2026 | A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument… |
| CVE-2026-5979 | High (7.4) | 1.2% | — | Apr 9, 2026 | A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the… |
| CVE-2026-2056 | Medium (5.5) | 0.96% | — | Feb 6, 2026 | A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of the component DHCP Connection Status… |
| CVE-2026-2055 | Medium (5.5) | 0.96% | — | Feb 6, 2026 | A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Client Information Handler. Executing a manipulation can lead to… |
| CVE-2026-2054 | Medium (5.5) | 0.96% | — | Feb 6, 2026 | A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Handler. Performing a manipulation results in information disclosure.… |
| CVE-2025-65731 | Medium (6.8) | 0.44% | — | Jan 8, 2026 | An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root… |
| CVE-2012-10021 | Critical (9.3) | 4.4% | — | Jul 31, 2025 | A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when… |
| CVE-2025-46176 | Medium (6.5) | 0.37% | — | May 23, 2025 | Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis. |
| CVE-2025-4445 | Medium (5.3) | 5.7% | — | May 9, 2025 | A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. The manipulation of the argument mac leads to command injection. It is possible to launch the… |
| CVE-2025-4443 | Medium (5.3) | 58% | — | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be… |
| CVE-2025-4442 | High (8.7) | 2.6% | — | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetWAN_Wizard55. The manipulation of the argument curTime leads to buffer overflow. The… |
| CVE-2025-4441 | High (8.7) | 2.6% | — | May 8, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formSetWAN_Wizard534. The manipulation of the argument curTime leads to buffer overflow. It is possible… |
| CVE-2025-2553 | Medium (5.3) | 1.3% | — | Mar 20, 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects some unknown processing of the file /goform/formVirtualServ. The manipulation leads to improper… |
| CVE-2025-2552 | Medium (5.3) | 0.77% | — | Mar 20, 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/formTcpipSetup. The manipulation leads to improper… |
| CVE-2025-2551 | Medium (5.3) | 0.77% | — | Mar 20, 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been classified as problematic. This affects an unknown part of the file /goform/formSetPortTr. The manipulation leads to improper access… |
| CVE-2025-2550 | Medium (5.3) | 0.77% | — | Mar 20, 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/formSetDDNS of the component DDNS Service. The… |
| CVE-2025-2549 | Medium (5.3) | 1.0% | — | Mar 20, 2025 | A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/formSetPassword. The manipulation… |
| CVE-2025-2548 | Medium (5.3) | 1.0% | — | Mar 20, 2025 | A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file /goform/formSetDomainFilter. The manipulation leads to improper… |
| CVE-2025-2547 | Medium (5.3) | 0.77% | — | Mar 20, 2025 | A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. This issue affects some unknown processing of the file /goform/formAdvNetwork. The manipulation leads to… |
| CVE-2025-2546 | Medium (5.3) | 11% | — | Mar 20, 2025 | A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The… |
| CVE-2024-11960 | High (8.7) | 1.8% | — | Nov 28, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime… |
| CVE-2024-11959 | High (8.7) | 1.8% | — | Nov 28, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime… |
| CVE-2024-9565 | High (8.7) | 2.0% | — | Oct 7, 2024 | A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the… |
| CVE-2024-9564 | High (8.7) | 1.9% | — | Oct 7, 2024 | A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.