Description
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
In plain language
AI Worth attentionIf you use a D-Link DIR-605L router with firmware older than 2.08UIBetaB01.bin, anyone on the network can send a simple web request and force it to reboot—causing a temporary outage. Small businesses should take action because it’s reachable without a login.
CVE-2017-9675 is a remote denial-of-service in D-Link DIR-605L firmware where an unauthenticated HTTP GET request can trigger an immediate reboot, leading to temporary loss of availability (router restarts).
What to do now
- Check your D-Link DIR-605L firmware version and confirm whether it is prior to 2.08UIBetaB01.bin.
- If it is older than 2.08UIBetaB01.bin, plan an immediate firmware update to the first fixed version: 2.08UIBetaB01.bin.
- After updating, verify the router stays online for a while and that firmware version now shows 2.08UIBetaB01.bin (or newer, if applicable).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-9675 and every CVE in our database. Create a free account — no credit card required.
Create Free Account