CVE-2025-8978

CWE-3453 documents3 sources
Severity
6.6MEDIUM
EPSS
0.4%
top 41.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14

Description

A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function FirmwareUpgrade of the component boa. The manipulation leads to insufficient verification of data authenticity. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5d-link/dir-619l6.02CN02

🔴Vulnerability Details

2
GHSA
GHSA-5j9f-jgfq-46gx: A vulnerability was determined in D-Link DIR-619L 62025-08-14
CVEList
D-Link DIR-619L boa FirmwareUpgrade data authenticity2025-08-14
CVE-2025-8978 (MEDIUM CVSS 6.6) | A vulnerability was determined in D | cvebase.io