CVE-2025-4453: D-Link DIR-619L formSysCmd command injection
A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function formSysCmd. The manipulation of the argument sysCmd leads to command injection. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4453?
CVE-2025-4453 has been classified as critical.
What does CVE-2025-4453 affect?
CVE-2025-4453 affects the D-Link DIR-619L router.
What is the nature of the vulnerability in CVE-2025-4453?
CVE-2025-4453 is a command injection vulnerability due to improper handling of the sysCmd argument.
Can CVE-2025-4453 be exploited remotely?
Yes, CVE-2025-4453 can be exploited remotely.
How can I mitigate CVE-2025-4453?
To mitigate CVE-2025-4453, it is advisable to update the D-Link DIR-619L to the latest firmware version provided by the vendor.