CVE-2025-4443: D-Link DIR-605L sub_454F2C command injection
Published May 8, 2025
·Updated
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
3 affected components
D-Link DIR-605L
All of the following
Dlink Dir-605l Firmware=2.13b01
Dlink Dir-605l
Event History
May 8, 2025
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionSeverityWeakness
May 9, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-4443?
CVE-2025-4443 has been rated as critical.
2
What type of vulnerability is CVE-2025-4443?
CVE-2025-4443 is a command injection vulnerability.
3
How can I exploit CVE-2025-4443?
CVE-2025-4443 can be exploited remotely through manipulation of the sysCmd argument.
4
How do I fix CVE-2025-4443?
The recommended fix for CVE-2025-4443 is to update to the latest firmware version provided by D-Link.
5
What devices are affected by CVE-2025-4443?
CVE-2025-4443 affects the D-Link DIR-605L running firmware version 2.13B01.