Dir 605l
Vendor:
First CVE: May 1, 2015 · Active for 11 years
67
Total CVEs
More Total CVEs than 98% of tracked products
8.4
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
3.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dir 605l over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2015
11 years ago
Most Recent CVE
May 4, 2026
82 days ago
CVE Severity & Scoring
Dir 605l67 CVEs
12%
69%
19%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network55 (82.1%)
Unknown0 (0.0%)
Physical1 (1.5%)
Adjacent Network11 (16.4%)
Attack Complexity
Low67 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None67 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low36 (53.7%)
High0 (0.0%)
None31 (46.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (67 CVEs).
67 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8361CRITICAL The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | May 1, 2015 | 9.8 | 98 | YES | YES |
CVE-2021-40655HIGH An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php | Sep 24, 2021 | 7.5 | 96 | YES | YES |
CVE-2025-4443CRITICAL A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to co | May 9, 2025 | 9.8 | 56 | NO | NO |
CVE-2012-10021CRITICAL A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises fro | Jul 31, 2025 | 9.8 | 43 | NO | YES |
CVE-2017-9675HIGH On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot. | Jun 15, 2017 | 7.5 | 40 | NO | YES |
CVE-2026-42373HIGH D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alpha | May 4, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-42372HIGH D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alpha | May 4, 2026 | 8.8 | 34 | NO | NO |
CVE-2018-20056CRITICAL An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-based buffer overflow allowing remote attackers to execute a | Dec 11, 2018 | 9.8 | 34 | NO | NO |
CVE-2026-5984HIGH A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulatio | Apr 9, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-5983HIGH A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Execut | Apr 9, 2026 | 8.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (67 CVEs).
CISA KEV
2 CVEs
3.0% of CVEs· 97th percentile
Metasploit
2 CVEs
3.0% of CVEs· 96th percentile
Nuclei
1 CVE
1.5% of CVEs· 96th percentile
ExploitDB
2 CVEs
3.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (67 CVEs).
Media Mentions
Signals from CVEs in this product scope (67 CVEs).
Top CNAs Publishing CVEs For Dir 605l
Top CWEs
Versions
No cataloged versions.