10
CVE-2015-1187
- EPSS 82.86%
- Veröffentlicht 21.09.2017 16:29:00
- Zuletzt bearbeitet 21.04.2026 18:55:58
- Erkennungen
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dlink ≫ Dir-626l Firmware Version 1.04 Update b04
Dlink ≫ Dir-636l Firmware Version 1.04
Dlink ≫ Dir-808l Firmware Version 1.03 Update b05
Dlink ≫ Dir-810l Firmware Version 1.01 Update b04
Dlink ≫ Dir-810l Firmware Version 2.02 Update b01
Dlink ≫ Dir-820l Firmware Version 1.02 Update b10
Dlink ≫ Dir-820l Firmware Version 1.05 Update b03
Dlink ≫ Dir-820l Firmware Version 2.01 Update b02
Dlink ≫ Dir-826l Firmware Version 1.00 Update b23
Dlink ≫ Dir-830l Firmware Version 1.00 Update b07
Dlink ≫ Dir-836l Firmware Version 1.01 Update b03
Trendnet ≫ Tew-731br Firmware Version 2.01 Update b01
Dlink ≫ Dir-651 Firmware Version 1.10na Update b02
Trendnet ≫ Tew-651br Firmware Version -
Trendnet ≫ Tew-652br Firmware Version -
Trendnet ≫ Tew-711br Firmware Version 1.00 Update b31
Trendnet ≫ Tew-810dr Firmware Version 1.00 Update b19
Trendnet ≫ Tew-813dru Firmware Version 1.00 Update b23
25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
SchwachstelleThe ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
BeschreibungThe impacted product is end-of-life and should be disconnected if still in use.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 82.86% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://packetstormsecurity.com/files/130607/D-Link-DIR636L-Remote-Command-Injection.html
http://packetstormsecurity.com/files/131465/D-Link-TRENDnet-NCC-Service-Command-Injection.html
http://seclists.org/fulldisclosure/2015/Mar/15
http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10052
http://www.securityfocus.com/bid/72848
https://github.com/darkarnium/secpub/tree/master/Multivendor/ncc2
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1187