CVE-2013-7389

EXPLOITED

D-Link DIR-645 < 1.04B11 - Cross-Site Scripting via Parental Controls Bind Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-7389 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including Roberto Paleari, Roberto Paleari, Craig Heffner, including a Metasploit module exploits/linux/http/dlink_authentication_cgi_bof.

AI-analyzed exploit summary The exploit details multiple vulnerabilities in D-Link DIR-645 firmware 1.03B08, including buffer overflows in 'post_login.xml', 'hedwig.cgi', and 'authentication.cgi', as well as XSS vulnerabilities in 'bind.php', 'info.php', and 'bsc_sms_send.php'. Proof-of-concept commands are provided for each vulnerability, demonstrating remote code execution and cross-site scripting.

Description

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceid parameter to parentalcontrols/bind.php, (2) RESULT parameter to info.php, or (3) receiver parameter to bsc_sms_send.php.

Exploits (3)

exploitdb WORKING POC
by Roberto Paleari · textwebappshardware
https://www.exploit-db.com/exploits/27283

The exploit details multiple vulnerabilities in D-Link DIR-645 firmware 1.03B08, including buffer overflows in 'post_login.xml', 'hedwig.cgi', and 'authentication.cgi', as well as XSS vulnerabilities in 'bind.php', 'info.php', and 'bsc_sms_send.php'. Proof-of-concept commands are provided for each vulnerability, demonstrating remote code execution and cross-site scripting.

Classification
Working Poc 90%
Attack Type
Rce | Xss
Complexity
Moderate
Reliability
Reliable
Target: D-Link DIR-645, firmware 1.03B08
No auth needed
Prerequisites: Network access to the target device · Curl or similar HTTP client
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Roberto Paleari, Craig Heffner · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/dlink_authentication_cgi_bof.rb

This Metasploit module exploits a buffer overflow vulnerability in D-Link routers via the authentication.cgi endpoint by sending a maliciously crafted POST request with an overly long password field. It achieves remote code execution (RCE) by leveraging a cmdstager to execute arbitrary commands on the target device.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DIR-645 firmware 1.03 (and other vulnerable firmwares such as DIR865LA1_FW101b06 and DIR845LA1_FW100b20)
No auth needed
Prerequisites: Network access to the vulnerable D-Link router · Target device must be running vulnerable firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Roberto Paleari, Craig Heffner · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/dlink_hedwig_cgi_bof.rb

This Metasploit module exploits a buffer overflow vulnerability in D-Link routers via the hedwig.cgi endpoint by sending a maliciously crafted cookie header. It achieves remote code execution by leveraging a stack-based overflow to control the instruction pointer and execute arbitrary commands.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DIR-645 v1.03, DIR-300 v2.14, DIR-600
No auth needed
Prerequisites: Network access to the vulnerable D-Link router · hedwig.cgi endpoint must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/95953
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/95952
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/95910
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61579

Scores

EPSS 0.9223
EPSS Percentile 99.7%

Details

VulnCheck KEV 2021-04-12
CWE
CWE-79
Status published
Products (2)
dlink/dir-645 a1
dlink/dir-645_firmware < 1.03
Published Jul 07, 2014
Tracked Since Feb 18, 2026