SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2014-100005

D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

KEVHIGH 8.0EPSS 48.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 June 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

CVSS 3.1
8.0 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
48.15% probability · 99th percentile
CISA KEV
Listed 16 May 2024 · due 6 June 2024
Weakness
CWE-352
Affected
dlink/dir-600 firmware
Source
cve@mitre.org

CISA notes

This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. https://legacy.us.dlink.com/pages/product.aspx?id=4587b63118524aec911191cc81605283; https://nvd.nist.gov/vuln/detail/CVE-2014-100005

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.