CVE-2025-4443 is a critical command injection vulnerability affecting the D-Link DIR-605L router (firmware 2.13B01) in the sub_454F2C function via manipulation of the sysCmd argument. With a CVSS score of 9.8, this remotely exploitable flaw requires no user interaction and could lead to complete compromise of confidentiality, integrity, and availability. While the vendor was notified and the product is unsupported, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion is minimal, with only one mention unrelated to the D-Link vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.13b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-605l_firmware:2.13b01:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.