Skip to content
COOEY

EXPOSURES › CVE-2014-100005

CVE-2014-100005

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-100005 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildsupply-chainunpatched

D-Link DIR-600 routers contain a CVE-2014-100005 CSRF vulnerability that allows attackers to hijack admin sessions and change router configurations.

This vulnerability enables attackers to modify router settings by exploiting compromised admin sessions, posing a supply chain risk for DIB vendors relying on D-Link hardware. While not an RCE or zero-day, the active exploitation status and D-Link's history of critical firmware flaws warrant immediate firmware updates and supply chain vetting.

Shame score — Active exploitation of a known, non-RCE vulnerability in a vendor with a history of critical firmware flaws.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.