CVE-2014-100005 KEV
8.0
HIGH · CVSS 3.1 · EPSS 43.5% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2024-06-06.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Scoring
| CVSS | 8.0 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 43.46% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | yes — remediate by 2024-06-06 |
| Public exploit | none known |
| Published | 2015-01-13 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability |
|---|---|
| Added | 2024-05-16 |
| Due | 2024-06-06 |
| Vendor / product | D-Link / DIR-600 Router |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| dlink | dir-600 |
| dlink | dir-600 firmware |
References
- http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/
- http://secunia.com/advisories/57304
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91794
- http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/
- http://secunia.com/advisories/57304
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91794
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-100005
→ the Explorer · watch your stack · NVD