Junglewise Threat Intelligence

CVE-2014-100005: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

CVE-2014-100005 · Severity: critical · CVSS 8 · Exploited in the wild · Published 2024-05-16

Vendors: D-Link.

Executive brief

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 routers allow remote attackers to hijack administrator sessions. Successful exploitation can lead to unauthorized account creation, remote management enablement, configuration changes via hedwig.cgi and pigwidgeon.cgi, or diagnostic ping execution.

Affected products

  • D-Link DIR-600 (rev. Bx) firmware before 2.17b02

Timeline

  • 2015-01-13: disclosed: Initial NVD analysis and CVSS v2 assignment
  • 2024-05-16: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2024-05-16: advisory: Published date listed in advisory summary
  • 2024-08-01: other: CISA-ADP updated CVSS v3.1 and CWE information