cbcvebase.

D-Link Dir-605L Firmware vulnerabilities

4 known vulnerabilities affecting d-link/dir-605l_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH3

Vulnerabilities

Page 1 of 1
CVE-2018-20057P2HIGHCVSS 8.8Exploitedv2.12b12018-12-11
CVE-2018-20057 [HIGH] CWE-78 CVE-2018-20057: An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 device An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated users to execute arbitrary OS commands via the sysCmd POST parameter.
nvd
CVE-2018-20056P2CRITICALCVSS 9.8v2.12b12018-12-11
CVE-2018-20056 [CRITICAL] CWE-787 CVE-2018-20056: An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 device An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-based buffer overflow allowing remote attackers to execute arbitrary code without authentication via the goform/formLanguageChange currTime parameter.
nvd
CVE-2026-42373P3HIGHCVSS 8.8vB22026-05-04
CVE-2026-42373 [HIGH] CWE-798 CVE-2026-42373: D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The de D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn76_dlwbr_dir605L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom lo
nvd
CVE-2026-42372P3HIGHCVSS 8.8vA12026-05-04
CVE-2026-42372 [HIGH] CWE-798 CVE-2026-42372: D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The de D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom lo
nvd