6.8

CVE-2025-65731

Exploit
An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root terminal access on a serial interface without proper access control.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dlink ≫ Dir-605l Firmware Version 6.02cn02
   Dlink ≫ Dir-605l Version f1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://www.dlink.com/en/security-bulletin/
Product
https://www.dlink.com/uk/en/products/dir-605l-wireless-n-300-home-cloud-router
Product
https://gist.github.com/whitej3rry/f142a93bac360f9b1126f552f64957ea
Third Party Advisory
Exploit
https://github.com/whitej3rry/CVE-2025-65731
Third Party Advisory
Exploit