D-Link DIR-605L
cpe:2.3:h:d-link:dir-605l:*:*:*:*:*:*:*, +3 more
- 2.13B01
A critical command injection vulnerability has been identified in the D-Link DIR-605L router, specifically in version 2.13B01. The issue arises in the wake-on-lan function, where improper handling of the MAC address argument allows for remote command injection. This vulnerability affects devices that are no longer supported by the vendor.
Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the affected device.
To reproduce this vulnerability, send a request to the DIR-605L router's wake-on-lan function with a crafted MAC address that exploits the command injection flaw. This can be done remotely, targeting the specific version 2.13B01.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.