CVE-2014-100005
D-Link DIR-600 Router: Cross-Site Request Forgery (CSRF)
As of , CVE-2014-100005 in D-Link DIR-600 Router is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 16 May 2024
- US federal deadline
- 6 June 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.43Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.42 on 16 May 2024EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: legacy.us.dlink.comLinks below, from CISA's entry.
What CISA says to do
This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
CISA's required action
What the flaw is
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
CISA's description
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
The CVE record's description, from mitre
- CVE published
- 13 January 2015
- Assigned by
- mitre
- CVSS
- 8.0 High (CVSS 3.1, from CISA-ADP)
- CWE-352
- Cross-Site Request Forgery (CSRF)
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: D-Link DIR-645 / DIR-815 diagnostic.php Command Executionexploit module, rank excellent
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org