Skip to content
COOEY

EXPOSURES › CVE-2015-2051

CVE-2015-2051

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-02-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-2051 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

D-Link DIR-645 routers allow remote attackers to execute arbitrary commands via the HNAP interface, a flaw actively exploited in the wild.

The DIR-645 router's HNAP interface permits remote code execution without authentication, enabling attackers to take full control of the device. DIB organizations must care because unpatched RCE flaws in networking hardware are frequently exploited in the wild, leading to botnet recruitment, lateral movement, and compromised network perimeters. Organizations should replace legacy D-Link hardware, enforce strict network segmentation, and monitor for known exploit signatures.

Shame score — D-Link repeatedly ships firmware with critical RCE flaws that remain unpatched for extended periods and are actively exploited in the wild, demonstrating a systemic failure in vulnerability management and a negligent disregard for customer security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.