CVE-2014-100005
KEVmassCSRF in D-Link DIR-600 Router Allows Unauthorized Configuration Changes
CISA: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
The D-Link DIR-600 router contains a cross-site request forgery (CSRF) flaw, CWE-352, in its administrative web interface. An attacker triggers it by inducing a user with an active administrator session to the router to load attacker-controlled content, which silently submits forged configuration-change requests using the hijacked admin session. A successful attack lets the attacker alter the router's configuration, potentially redirecting traffic or establishing persistence on the device. All associated hardware revisions of the DIR-600 are legacy end-of-life/end-of-service products, so users of this model are affected. CISA added the issue to the KEV catalog on 2024-05-16, indicating observed exploitation, and EPSS assigns a 42.4% probability of exploitation in the next 30 days (99th percentile); ransomware use is unknown.
What to do: Because the DIR-600 is end-of-life/end-of-service and the data indicates no fixed firmware, CISA's required action is to retire and replace affected hardware per vendor instructions. If replacement must be deferred, disable WAN/remote administration, avoid staying logged in to the admin interface while browsing other sites, restrict admin access to trusted clients, and check the device's DNS settings and administrator credentials for signs of tampering.
| D-Link DIR-600 Router | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
- Affected
- D-Link DIR-600 Router
- Required action
- This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- D-Link
- Products
- DIR-600 Router
- Weakness
- CWE-352