Junglewise Threat Intelligence

CVE-2015-1187: D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

CVE-2015-1187 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Geovision Multiple Devices. Vendors: TRENDnet, D-Link, Geovision.

Executive brief

The ping tool in multiple D-Link and TRENDnet devices contains a remote code execution vulnerability. Attackers can execute arbitrary commands via the ping_addr parameter to the ping.ccp component.

Affected products

  • D-Link DIR-626L 1.04:b04
  • D-Link DIR-636L 1.04
  • D-Link DIR-651 1.10na:b02
  • TRENDnet Multiple Devices

Timeline

  • 2015-03-01: disclosed: Initial public disclosure via seclists and packetstorm
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats