ZeroHour

CVE-2014-100005

KEVmass

CSRF in D-Link DIR-600 Router Allows Unauthorized Configuration Changes

CISA: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

CVSS
EPSS
48%p99
Published
KEV added
AI analysis

The D-Link DIR-600 router contains a cross-site request forgery (CSRF) flaw, CWE-352, in its administrative web interface. An attacker triggers it by inducing a user with an active administrator session to the router to load attacker-controlled content, which silently submits forged configuration-change requests using the hijacked admin session. A successful attack lets the attacker alter the router's configuration, potentially redirecting traffic or establishing persistence on the device. All associated hardware revisions of the DIR-600 are legacy end-of-life/end-of-service products, so users of this model are affected. CISA added the issue to the KEV catalog on 2024-05-16, indicating observed exploitation, and EPSS assigns a 42.4% probability of exploitation in the next 30 days (99th percentile); ransomware use is unknown.

What to do: Because the DIR-600 is end-of-life/end-of-service and the data indicates no fixed firmware, CISA's required action is to retire and replace affected hardware per vendor instructions. If replacement must be deferred, disable WAN/remote administration, avoid staying logged in to the admin interface while browsing other sites, restrict admin access to trusted clients, and check the device's DNS settings and administrator credentials for signs of tampering.

Affected
D-Link DIR-600 Router
Estimated exposure
massplausibly millions of legacy units worldwide, with hundreds of thousands of legacy D-Link devices still visible in public internet scans — No active-install count is published, so the estimate rests on the DIR-600's history as one of D-Link's most widely distributed budget routers and on public internet scans that routinely surface large numbers of legacy D-Link devices still…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.

CISA Known Exploited Vulnerability
Affected
D-Link DIR-600 Router
Required action
This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
D-Link
Products
DIR-600 Router
Weakness
CWE-352

In the news