Executive brief
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 routers allow remote attackers to hijack administrator sessions. Successful exploitation can lead to unauthorized account creation, remote management enablement, configuration changes via hedwig.cgi and pigwidgeon.cgi, or diagnostic ping execution.
Affected products
- D-Link DIR-600 (rev. Bx) firmware before 2.17b02
Timeline
- 2015-01-13: disclosed: Initial NVD analysis and CVSS v2 assignment
- 2024-05-16: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2024-05-16: advisory: Published date listed in advisory summary
- 2024-08-01: other: CISA-ADP updated CVSS v3.1 and CWE information