Executive brief
The ping tool in multiple D-Link and TRENDnet devices contains a remote code execution vulnerability. Attackers can execute arbitrary commands via the ping_addr parameter to the ping.ccp component.
Affected products
- D-Link DIR-626L 1.04:b04
- D-Link DIR-636L 1.04
- D-Link DIR-651 1.10na:b02
- TRENDnet Multiple Devices
Timeline
- 2015-03-01: disclosed: Initial public disclosure via seclists and packetstorm
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog