CVE-2014-125117

CRITICAL

D-Link DSP-W215 1.02 - Unauthenticated Stack-based Buffer Overflow via /common/info.cgi HTTP POST Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-125117. PoCs published by Metasploit, Craig Heffner, including Metasploit module exploits/linux/http/dlink_dspw215_info_cgi_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in D-Link devices via a crafted POST request to /common/info.cgi, leading to remote code execution. It targets the my_cgi.cgi component and has been tested on D-Link DSP-W215.

Description

A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with system-level privileges.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotehardware
https://www.exploit-db.com/exploits/34063

This Metasploit module exploits a stack-based buffer overflow in D-Link devices via a crafted POST request to /common/info.cgi, leading to remote code execution. It targets the my_cgi.cgi component and has been tested on D-Link DSP-W215.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DSP-W215 v1.02
No auth needed
Prerequisites: Network access to the vulnerable device · Target device must be running the vulnerable firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Craig Heffner · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/dlink_dspw215_info_cgi_bof.rb

This Metasploit module exploits a stack-based buffer overflow in D-Link devices via a crafted POST request to /common/info.cgi, leading to remote code execution. It targets the my_cgi.cgi component and has been tested on D-Link DSP-W215.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DSP-W215 v1.02
No auth needed
Prerequisites: Network access to the vulnerable device · Target device must be running the affected firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.6255
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-121 CWE-20
Status published
Products (2)
D-Link/DSP-W215 1.02
dlink/dsp-w215_firmware 1.02
Published Jul 25, 2025
Tracked Since Feb 18, 2026