CVE-2025-46176: Command Injection
Published May 23, 2025
·Updated
Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.
Affected Software
6 affected components
D-Link DIR-605L
D-Link DIR-816L
All of the following
Dlink Dir-605l Firmware=2.13b01
Dlink Dir-605l
All of the following
Dlink Dir-816l Firmware=2.06b01
Dlink DIR-816L
Event History
May 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-46176?
CVE-2025-46176 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2025-46176?
To mitigate CVE-2025-46176, ensure that the affected D-Link router firmware is updated to the latest version provided by the manufacturer.
3
What products are affected by CVE-2025-46176?
CVE-2025-46176 affects the D-Link DIR-605L and DIR-816L routers with specific firmware versions.
4
What vulnerabilities does CVE-2025-46176 introduce?
CVE-2025-46176 introduces vulnerabilities due to hardcoded credentials that allow unauthorized remote command execution.
5
Is CVE-2025-46176 being actively exploited?
As of the latest updates, CVE-2025-46176 has not been publicly reported as actively exploited, but the risk remains significant.