CVE-2025-2547 is an improper access control vulnerability affecting D-Link DIR-618 and DIR-605L routers running firmware versions 2.02/3.02. This flaw, found in the /goform/formAdvNetwork file processing, allows an unauthenticated attacker on the local network to achieve limited integrity impact. Rated as Medium severity with a CVSS score of 4.3, the vulnerability requires local network access (AV:A) and has low attack complexity (AC:L), but only results in a low impact to integrity (I:L) with no confidentiality or availability impact. It specifically targets products no longer supported by the vendor. While the exploit has been publicly disclosed, there are no known Metasploit modules, Nuclei templates, or ExploitDB entries. Community discussion and media coverage are minimal, and it is not listed in the CISA KEV catalog, suggesting limited active exploitation or widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-618_firmware:2.02:*:*:*:*:*:*:* | ||
3.02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-605l_firmware:3.02:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.