Junglewise Threat Intelligence

CVE-2015-2051: D-Link DIR-645 Router Remote Code Execution Vulnerability

CVE-2015-2051 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-02-10

Vendors: D-Link.

Executive brief

The D-Link DIR-645 router is vulnerable to remote code execution via the HNAP interface. Attackers can execute arbitrary commands by sending a specially crafted GetDeviceSettings action.

Affected products

  • D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier

Timeline

  • 2015-02-24: disclosed: Initial NIST analysis and CVSS assignment
  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog