EXPOSURES › CVE-2014-100005
CVE-2014-100005
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link DIR-600 routers contain a CVE-2014-100005 CSRF vulnerability that allows attackers to hijack admin sessions and change router configurations.
This vulnerability enables attackers to modify router settings by exploiting compromised admin sessions, posing a supply chain risk for DIB vendors relying on D-Link hardware. While not an RCE or zero-day, the active exploitation status and D-Link's history of critical firmware flaws warrant immediate firmware updates and supply chain vetting.
Shame score — Active exploitation of a known, non-RCE vulnerability in a vendor with a history of critical firmware flaws.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.