CVE-2025-2546
medium · 5.3A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The manipulation leads to improper access controls. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
5.3
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2025-03-20
Published
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-266CWE-284
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| dlink | dir-605l_firmware | 3.02 |
| dlink | dir-605l | all versions |
| dlink | dir-618_firmware | 2.02 |
| dlink | dir-618 | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://lavender-bicycle-a5a.notion.site/D-Link-DIR-605L-formAdvFirewall-1b153a41781f80aca28ec11da787f0e8?pvs=4
- https://lavender-bicycle-a5a.notion.site/D-Link-DIR-618-formAdvFirewall-1b053a41781f801ca1a5e09bb83a22c5?pvs=4
- https://vuldb.com/?ctiid.300160
- https://vuldb.com/?id.300160
- https://vuldb.com/?submit.516788
- https://www.dlink.com/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-2546