Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev
Published Jan 13, 2015 ·Due Jun 6, 2024
8.0
HIGHCVSS 3.1
EPSS 43.46%
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Affected products
No data.
- ≤ 2.16ww
-
- Version 0StatusaffectedConstraints<*
- Version
-
- Version 0StatusaffectedConstraints<=2.16ww
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| D-Link | Dir-600 | n/a |
| ||||||
| D-Link | Dir-600 Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Date Added
May 16, 2024
Patch Due
Jun 6, 2024
Required Action
This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jul 30, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (28 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 43.46% (0.43456) | 98.70th | v5 (v2026.06.15) |
| Sep 18, 2026 | 43.46% (0.43456) | 98.68th | v5 (v2026.06.15) |
| Sep 12, 2026 | 48.15% (0.48146) | 98.79th | v5 (v2026.06.15) |
| Sep 11, 2026 | 43.46% (0.43456) | 98.66th | v5 (v2026.06.15) |
| Aug 5, 2026 | 42.41% (0.42414) | 98.57th | v5 (v2026.06.15) |
| Jul 18, 2026 | 47.07% (0.47071) | 98.70th | v5 (v2026.06.15) |
| Jun 15, 2026 | 42.41% (0.42414) | 98.52th | v5 (v2026.06.15) |
| Apr 23, 2026 | 45.31% (0.45306) | 97.62th | v4 (v2025.03.14) |
| Feb 1, 2026 | 40.76% (0.40758) | 97.29th | v4 (v2025.03.14) |
| Jun 25, 2025 | 35.95% (0.35954) | 96.90th | v4 (v2025.03.14) |
| Jun 24, 2025 | 39.25% (0.39245) | 97.11th | v4 (v2025.03.14) |
| Mar 30, 2025 | 31.12% (0.31121) | 96.36th | v4 (v2025.03.14) |
| Mar 29, 2025 | 56.72% (0.56718) | 97.28th | v4 (v2025.03.14) |
| Mar 28, 2025 | 31.12% (0.31121) | 96.36th | v4 (v2025.03.14) |
| Mar 27, 2025 | 56.72% (0.56718) | 97.82th | v4 (v2025.03.14) |
| Mar 23, 2025 | 31.12% (0.31121) | 96.22th | v4 (v2025.03.14) |
| Mar 20, 2025 | 28.20% (0.28196) | 96.10th | v4 (v2025.03.14) |
| Mar 19, 2025 | 53.60% (0.53595) | 97.68th | v4 (v2025.03.14) |
| Mar 17, 2025 | 22.81% (0.22812) | 95.42th | v4 (v2025.03.14) |
| Dec 17, 2024 | 64.22% (0.64216) | 98.03th | v3 (v2023.03.01) |
| Aug 25, 2024 | 87.85% (0.87852) | 98.73th | v3 (v2023.03.01) |
| Jul 9, 2024 | 85.66% (0.85658) | 98.59th | v3 (v2023.03.01) |
| May 19, 2024 | 86.06% (0.86063) | 98.56th | v3 (v2023.03.01) |
| May 17, 2024 | 87.85% (0.87852) | 98.65th | v3 (v2023.03.01) |
| Nov 9, 2023 | 42.13% (0.42130) | 96.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.24% (0.01244) | 83.35th | v3 (v2023.03.01) |
| Mar 6, 2023 | 37.47% (0.37470) | 97.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 37.47% (0.37470) | 97.10th | v2 (v2022.01.01) |
References (5)
- http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/ x_refsource_MISCExploitThird Party Advisory
- http://secunia.com/advisories/57304 third-party-advisoryx_refsource_SECUNIABroken Link
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018 x_refsource_CONFIRMPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91794 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-100005 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/ | x_refsource_MISCExploitThird Party Advisory | |
| http://secunia.com/advisories/57304 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/91794 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-100005 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.