PT-2025-33406 · D Link · D-Link Dir-619L

Iot_Res

·

Published

2025-08-14

·

Updated

2025-08-15

·

CVE-2025-8978

CVSS v2.0
6.8
VectorAV:N/AC:H/Au:M/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

D-Link DIR-619L version 6.02CN02

Description:

A vulnerability exists in the `FirmwareUpgrade` function of the `boa` component, leading to insufficient verification of data authenticity. The attack can be launched remotely, but is considered difficult to exploit. The exploit has been publicly disclosed. This vulnerability affects products that are no longer supported by the maintainer.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2025-8978

Affected Products

D-Link Dir-619L