CVE-2014-100005

D-Link DIR-600 Router: Cross-Site Request Forgery (CSRF)

As of , CVE-2014-100005 in D-Link DIR-600 Router is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 16 May 2024
US federal deadline
6 June 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.43Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.42 on 16 May 2024EPSS on the day CISA listed it.
Public exploit
1 Metasploit module
Fix
Vendor advice: legacy.us.dlink.comLinks below, from CISA's entry.

What CISA says to do

This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CISA's required action

What the flaw is

D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.

CISA's description

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

The CVE record's description, from mitre

CVE published
13 January 2015
Assigned by
mitre
CVSS
8.0 High (CVSS 3.1, from CISA-ADP)
CWE-352
Cross-Site Request Forgery (CSRF)
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Read further