CVE-2015-1187
KEVmassUnauthenticated RCE via Ping Tool in D-Link and TRENDnet Routers
CISA: D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
The built-in ping tool in multiple D-Link and TRENDnet devices can be abused by remote attackers to execute arbitrary code on the device; the flaw is mapped to CWE-287 (improper authentication), indicating the diagnostic ping interface can be reached without valid credentials. An attacker triggers it by sending crafted requests to the device's web-based ping/diagnostic function and injecting commands, gaining full code execution on the router, typically as a foothold for botnet recruitment, traffic interception, or pivoting into the network behind the device. Only D-Link and TRENDnet products are affected, and CISA notes the impacted devices are end-of-life and will not receive fixes. The issue is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), signaling confirmed exploitation in the wild, and its 82.9% EPSS score (100th percentile) indicates very high near-term exploitation likelihood; ransomware use is unknown, though router-targeting botnets such as the Mirai-based IZ1H9 are actively adding payloads for these device classes.
What to do: Replace or disconnect affected D-Link and TRENDnet devices, which are end-of-life per CISA and will not receive vendor fixes; if replacement must wait, stop exposing the management interface to the internet and restrict the diagnostic/ping function to trusted networks. Review device logs and outbound traffic for signs of compromise or botnet activity (e.g., Mirai-family scanning). Because specific affected/fixed versions are not listed in the source data, confirm your model against vendor advisories before taking action.
| D-Link | — |
| TRENDnet | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
- Affected
- D-Link and TRENDnet Multiple Devices
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- D-Link and TRENDnet
- Products
- Multiple Devices
- Weakness
- CWE-287