CISA adds D-Link DIR router flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2014-100005 | CSRF in D-Link DIR-600 Router Allows Unauthorized Configuration Changes The D-Link DIR-600 router contains a cross-site request forgery (CSRF) flaw, CWE-352, in its administrative web interface. An attacker triggers it by inducing a user with an active administrator session to the router to load attacker-controlled content, which silently submits forged configuration-change requests using the hijacked admin session. A successful attack lets the attacker alter the router's configuration, potentially redirecting traffic or establishing persistence on the device. All associated hardware revisions of the DIR-600 are legacy end-of-life/end-of-service products, so users of this model are affected. CISA added the issue to the KEV catalog on 2024-05-16, indicating observed exploitation, and EPSS assigns a 42.4% probability of exploitation in the next 30 days (99th percentile); ransomware use is unknown. Do: Because the DIR-600 is end-of-life/end-of-service and the data indicates no fixed firmware, CISA's required action is to retire and replace affected hardware per vendor instructions. If replacement must be deferred, disable WAN/remote administration, avoid staying logged in to the admin interface while browsing other sites, restrict admin access to trusted clients, and check the device's DNS settings and administrator credentials for signs of tampering. | — | 48% | KEV |
| massplausibly millions of legacy units worldwide, with hundreds of thousands of legacy D-Link devices still visible in public internet scans | |
| CVE-2021-40655 | Unauthenticated credential disclosure in D-Link DIR-605 router (getcfg.php) CVE-2021-40655 is an unauthenticated information-disclosure flaw (CWE-863, incorrect authorization) in D-Link DIR-605 routers running B2 hardware revision firmware version 2.01MT. An attacker can trigger it remotely by forging a crafted POST request to the device's /getcfg.php page, with no credentials or user interaction required. The flaw returns the router's user name and password, giving the attacker valid credentials for the device's management interface and exposing confidential configuration data; the CVSS 7.5 score reflects high confidentiality impact with no direct integrity or availability impact. Only the legacy DIR-605 is affected, and per CISA all associated hardware revisions have reached end-of-life/end-of-service, so no fixed firmware should be expected from the vendor. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-05-16 amid headlines warning of actively exploited D-Link router flaws, a public proof-of-concept exists on GitHub, and EPSS assigns an 86.7% probability of exploitation within 30 days (percentile 100); ransomware use is unknown. Do: Because the DIR-605 is end-of-life/end-of-service with no fixed firmware available, CISA's required action is to retire and replace affected units per vendor instructions. As interim mitigation, restrict or disable WAN-side (internet-facing) management so /getcfg.php is unreachable from the internet, and rotate any exposed administrative credentials. Defenders with internet-facing D-Link routers should inventory against this KEV entry and prioritize replacement of remaining DIR-605 units. | 7.5 | 87% | KEV PoC |
| largetens of thousands of internet-exposed legacy units (estimated; the historical deployed base is likely far larger) |
Full article221 words · extracted from securityaffairs.com · click to collapse

CISA adds two D-Link DIR-600 and DIR-605 router vulnerabilities to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following D-Link router vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2014-100005 Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
- CVE-2021-40655 An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix these vulnerabilities by June 6, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/163289/security/cisa-d-link-dir-known-exploited-vulnerabilities-catalog.html