EXPOSURES › CVE-2015-1187
CVE-2015-1187
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link and TRENDnet devices suffered a remote code execution flaw in their ping tool that was actively exploited in the wild.
A remote code execution vulnerability in the ping tool of multiple D-Link and TRENDnet devices allowed attackers to execute arbitrary code remotely. This failure is critical for DIB organizations because it represents a known, unpatched threat that was actively exploited, directly impacting CMMC compliance by exposing systems to remote compromise and data theft. Organizations must rigorously patch networking hardware and monitor for active exploitation of known CVEs to prevent similar breaches.
Shame score — The vulnerability was actively exploited in the wild and linked to the KEV catalog, indicating negligent patching and avoidable exposure for a major networking vendor.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.