CVE-2015-2051
HIGH KEVD-Link DIR-645 Firmware < 1.05b01 - Remote Code Execution via HNAP GetDeviceSettings Action
Title source: llmExploitation Summary
CVE-2015-2051 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 10, 2022.
EIP tracks 2 public exploits from researchers including Metasploit, Samuel Huntley, Craig Heffner, including a Metasploit module exploits/linux/http/dlink_hnap_header_exec_noauth.
AI-analyzed exploit summary This Metasploit module exploits a blind OS command injection vulnerability in D-Link routers via the HNAP SOAP interface. It uses the SOAPAction header to inject commands, tested on DIR-645 and other models.
Description
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
Exploits (2)
This Metasploit module exploits a blind OS command injection vulnerability in D-Link routers via the HNAP SOAP interface. It uses the SOAPAction header to inject commands, tested on DIR-645 and other models.
This Metasploit module exploits a blind OS command injection vulnerability in D-Link routers via the HNAP SOAP interface. It leverages the SOAPAction header to execute arbitrary commands without authentication.
References (6)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H