ZeroHour

CVE-2015-1187

KEVmass

Unauthenticated RCE via Ping Tool in D-Link and TRENDnet Routers

CISA: D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

CVSS
EPSS
83%p100
Published
KEV added
AI analysis

The built-in ping tool in multiple D-Link and TRENDnet devices can be abused by remote attackers to execute arbitrary code on the device; the flaw is mapped to CWE-287 (improper authentication), indicating the diagnostic ping interface can be reached without valid credentials. An attacker triggers it by sending crafted requests to the device's web-based ping/diagnostic function and injecting commands, gaining full code execution on the router, typically as a foothold for botnet recruitment, traffic interception, or pivoting into the network behind the device. Only D-Link and TRENDnet products are affected, and CISA notes the impacted devices are end-of-life and will not receive fixes. The issue is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), signaling confirmed exploitation in the wild, and its 82.9% EPSS score (100th percentile) indicates very high near-term exploitation likelihood; ransomware use is unknown, though router-targeting botnets such as the Mirai-based IZ1H9 are actively adding payloads for these device classes.

What to do: Replace or disconnect affected D-Link and TRENDnet devices, which are end-of-life per CISA and will not receive vendor fixes; if replacement must wait, stop exposing the management interface to the internet and restrict the diagnostic/ping function to trusted networks. Review device logs and outbound traffic for signs of compromise or botnet activity (e.g., Mirai-family scanning). Because specific affected/fixed versions are not listed in the source data, confirm your model against vendor advisories before taking action.

Affected
D-Link
TRENDnet
Estimated exposure
masslikely in the millions of deployed devices (order of magnitude) — D-Link and TRENDnet are mass-market consumer/SOHO router vendors whose affected product lines have shipped millions of units, and internet-wide scans of this class of device routinely show hundreds of thousands of exposed web interfaces,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

CISA Known Exploited Vulnerability
Affected
D-Link and TRENDnet Multiple Devices
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
D-Link and TRENDnet
Products
Multiple Devices
Weakness
CWE-287

In the news