CVE-2025-14884 is a high-severity command injection vulnerability (CVSS 7.2) affecting the Firmware Update Service of the D-Link DIR-605 202WWB03 router, specifically impacting products no longer supported by the vendor. This flaw allows for remote, unauthenticated command injection, leading to high confidentiality, integrity, and availability impacts. While an exploit is publicly available, it is not yet listed in Metasploit or ExploitDB, and there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.02wwCPE matchmatch criteria | cpe:2.3:o:dlink:dir-605_firmware:2.02ww:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.