github.comrelatedexploit
https://github.com/LonTan0/CVE/blob/main/Remote%20Arbitrary%20Command%20Execution%20Vulnerability%20in%20ssdpcgi%20of%20D-Link%20DIR%E2%80%91600.md CVE-2026-2163
MEDIUM
D-Link DIR-600 ssdp.cgi command injection
Record summary
CVE-2026-2163 has a selected CVSS score of 5.1 (medium).
Description
A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DIR-600Browse D-Link / DIR-600 | CVE List | 2.15WWb02 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-2163 VDB-344865 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.344865 VDB-344865 | D-Link DIR-600 ssdp.cgi command injectionvdb entryTechnical description
https://vuldb.com/?id.344865 Submit #751764 | D-Link D-Link DIR-600 v2.15WWb02 Remote Arbitrary Command ExecutionThird-party advisory
https://vuldb.com/?submit.751764 dlink.comproduct
https://www.dlink.com/