« Back to list

Dlink

Dlink Dir-605l Firmware: vulnerabilities and CVEs

Dlink Dir-605l Firmware has 65 published vulnerabilities, 12 of them in the last 12 months. 8 are rated critical and 2 are listed by CISA as actively exploited.

CVEs65
Last 12 months12
Critical8
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-40655High (7.5)87%⚠ Active exploitationSep 24, 2021
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
CVE-2014-8361Critical (9.8)100%⚠ Active exploitationMay 1, 2015
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-42373High (8.8)0.98%—May 4, 2026
D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password…
CVE-2026-42372High (8.8)0.47%—May 4, 2026
D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password…
CVE-2026-5984High (7.4)1.2%—Apr 9, 2026
A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation of the argument curTime leads to…
CVE-2026-5983High (7.4)1.2%—Apr 9, 2026
A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing a manipulation of the argument…
CVE-2026-5982High (7.4)1.2%—Apr 9, 2026
A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the…
CVE-2026-5981High (7.4)1.2%—Apr 9, 2026
A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such manipulation of the argument curTime…
CVE-2026-5980High (7.4)1.2%—Apr 9, 2026
A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument…
CVE-2026-5979High (7.4)1.2%—Apr 9, 2026
A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the…
CVE-2026-2056Medium (5.5)0.96%—Feb 6, 2026
A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of the component DHCP Connection Status…
CVE-2026-2055Medium (5.5)0.96%—Feb 6, 2026
A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Client Information Handler. Executing a manipulation can lead to…
CVE-2026-2054Medium (5.5)0.96%—Feb 6, 2026
A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Handler. Performing a manipulation results in information disclosure.…
CVE-2025-65731Medium (6.8)0.44%—Jan 8, 2026
An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root…
CVE-2012-10021Critical (9.3)4.4%—Jul 31, 2025
A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when…
CVE-2025-46176Medium (6.5)0.37%—May 23, 2025
Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.
CVE-2025-4445Medium (5.3)5.7%—May 9, 2025
A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. The manipulation of the argument mac leads to command injection. It is possible to launch the…
CVE-2025-4443Medium (5.3)58%—May 9, 2025
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be…
CVE-2025-4442High (8.7)2.6%—May 9, 2025
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetWAN_Wizard55. The manipulation of the argument curTime leads to buffer overflow. The…
CVE-2025-4441High (8.7)2.6%—May 8, 2025
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formSetWAN_Wizard534. The manipulation of the argument curTime leads to buffer overflow. It is possible…
CVE-2025-2553Medium (5.3)1.3%—Mar 20, 2025
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects some unknown processing of the file /goform/formVirtualServ. The manipulation leads to improper…
CVE-2025-2552Medium (5.3)0.77%—Mar 20, 2025
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/formTcpipSetup. The manipulation leads to improper…
CVE-2025-2551Medium (5.3)0.77%—Mar 20, 2025
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been classified as problematic. This affects an unknown part of the file /goform/formSetPortTr. The manipulation leads to improper access…
CVE-2025-2550Medium (5.3)0.77%—Mar 20, 2025
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/formSetDDNS of the component DDNS Service. The…
CVE-2025-2549Medium (5.3)1.0%—Mar 20, 2025
A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/formSetPassword. The manipulation…
CVE-2025-2548Medium (5.3)1.0%—Mar 20, 2025
A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file /goform/formSetDomainFilter. The manipulation leads to improper…
CVE-2025-2547Medium (5.3)0.77%—Mar 20, 2025
A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. This issue affects some unknown processing of the file /goform/formAdvNetwork. The manipulation leads to…
CVE-2025-2546Medium (5.3)11%—Mar 20, 2025
A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The…
CVE-2024-11960High (8.7)1.8%—Nov 28, 2024
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime…
CVE-2024-11959High (8.7)1.8%—Nov 28, 2024
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime…
CVE-2024-9565High (8.7)2.0%—Oct 7, 2024
A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the…
CVE-2024-9564High (8.7)1.9%—Oct 7, 2024
A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services33
  2. T1059 Command and Scripting Interpreter32
  3. T1190 Exploit Public-Facing Application3
  4. T1078.001 Default Accounts2
  5. T1078 Valid Accounts1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Dlink