CVE-2025-14884
7.2D-Link · DIR-605
A command injection vulnerability in the D-Link DIR-605 firmware update service allows remote attackers to execute arbitrary commands.
Executive summary
A remote command injection vulnerability in the D-Link DIR-605 router poses a severe risk of unauthorized system control and potential compromise.
Vulnerability
The vulnerability exists within the firmware update service, where insufficient input validation allows an authenticated attacker with high privileges to perform command injection. This flaw enables the execution of arbitrary system commands on the affected hardware.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve full control over the router, potentially leading to unauthorized network access, data interception, or the use of the device as a pivot point for further attacks on the internal network. Given the CVSS score of 7.2, this represents a high-severity risk that could lead to significant operational disruption and a breach of network integrity.
Remediation
Immediate Action: Since the product is no longer supported by the manufacturer, the most effective remediation is to retire and replace the affected hardware immediately.
Proactive Monitoring: Monitor network traffic for unusual outbound connections or shell-like commands originating from the router's management interface.
Compensating Controls: Restrict access to the router administrative interface to trusted management IP addresses and ensure the device is not accessible from the public internet.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists via the researcher's technical write-up.
Analyst recommendation
Because the affected device is marked as end-of-life and no patch will be provided by the vendor, the device is permanently vulnerable. Organizations must prioritize the decommissioning of the D-Link DIR-605 from their network infrastructure to eliminate this critical security gap. Continued use of this hardware exposes the environment to persistent and unmitigated risk.
More D-Link CVEs
Sources
Originally found and disclosed by tian (VulDB User), per the CVE Program record.
- VDB-337372 | D-Link DIR-605 Firmware Update Service command injection Vulnerability database entry
- VDB-337372 | CTI Indicators (IOB, IOC, TTP)
- Submit #715465 | D-Link DIR605 B1v202WWB03 Command Injection Third-party advisory
- Exploit / PoC
- dlink.com