CVE-2014-100005
HIGH KEVDlink Dir-600 Firmware < 2.16ww - CSRF
Title source: ruleDescription
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/dlink_diagnostic_exec_noauth.rb
Scores
CVSS v3
8.0
EPSS
0.4531
EPSS Percentile
97.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-05-16
VulnCheck KEV
2024-05-16
InTheWild.io
2024-05-16
ENISA EUVD
EUVD-2014-1036
CWE
CWE-352
Status
published
Products (1)
dlink/dir-600_firmware
< 2.16ww
Published
Jan 13, 2015
KEV Added
May 16, 2024
Tracked Since
Feb 18, 2026