CVE-2025-2550: D-Link DIR-618/DIR-605L DDNS Service formSetDDNS access control
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/formSetDDNS of the component DDNS Service. The manipulation leads to improper access controls. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2550?
CVE-2025-2550 is classified as a problematic vulnerability due to improper access controls.
How do I fix CVE-2025-2550?
To fix CVE-2025-2550, it's recommended to update your D-Link DIR-618 or DIR-605L firmware to the latest secure version.
What are the affected products for CVE-2025-2550?
CVE-2025-2550 affects the D-Link DIR-618 and DIR-605L routers.
What kind of attacks does CVE-2025-2550 allow?
CVE-2025-2550 allows attackers to manipulate improper access controls, potentially leading to unauthorized access.
Who is affected by CVE-2025-2550?
Users of the D-Link DIR-618 and DIR-605L routers with the mentioned firmware versions are affected by CVE-2025-2550.