CVE CVE

CVE-2014-100005

CISA Known Exploited Vulnerability (KEV)

D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

May 16, 2024

June 6, 2024

This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

Weakness Enumeration

CWE-ID CWE Name

CWE-352
Cross-Site Request Forgery (CSRF)

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Not defined

CVSS v2

Base score:
6.8
Severity:

MEDIUM

Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P