A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Service. Performing manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Jan 2026 05:15:00 +0900

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-605
Dlink dir-605 Firmware
CPEs cpe:2.3:h:dlink:dir-605:b3:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-605_firmware:2.02ww:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-605
Dlink dir-605 Firmware

Fri, 19 Dec 2025 18:30:00 +0900

Type Values Removed Values Added
First Time appeared D-link
D-link dir-605
Vendors & Products D-link
D-link dir-605

Fri, 19 Dec 2025 04:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 19 Dec 2025 02:15:00 +0900

Type Values Removed Values Added
Description A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Service. Performing manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Title D-Link DIR-605 Firmware Update Service command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-12-18T18:51:29.216Z

Reserved: 2025-12-18T12:16:00.834Z

Link: CVE-2025-14884

cve-icon Vulnrichment

Updated: 2025-12-18T18:44:47.926Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-18T17:15:47.480

Modified: 2026-01-07T20:15:01.147

Link: CVE-2025-14884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-19T18:16:04Z

Weaknesses