10

CVE-2015-1187

Warnung
Exploit
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dlink ≫ Dir-626l Firmware Version 1.04 Update b04
   Dlink ≫ Dir-626l Version -
Dlink ≫ Dir-636l Firmware Version 1.04
   Dlink ≫ Dir-636l Version -
Dlink ≫ Dir-808l Firmware Version 1.03 Update b05
   Dlink ≫ Dir-808l Version -
Dlink ≫ Dir-810l Firmware Version 1.01 Update b04
   Dlink ≫ Dir-810l Version -
Dlink ≫ Dir-810l Firmware Version 2.02 Update b01
   Dlink ≫ Dir-810l Version -
Dlink ≫ Dir-820l Firmware Version 1.02 Update b10
   Dlink ≫ Dir-820l Version -
Dlink ≫ Dir-820l Firmware Version 1.05 Update b03
   Dlink ≫ Dir-820l Version -
Dlink ≫ Dir-820l Firmware Version 2.01 Update b02
   Dlink ≫ Dir-820l Version -
Dlink ≫ Dir-826l Firmware Version 1.00 Update b23
   Dlink ≫ Dir-826l Version -
Dlink ≫ Dir-830l Firmware Version 1.00 Update b07
   Dlink ≫ Dir-830l Version -
Dlink ≫ Dir-836l Firmware Version 1.01 Update b03
   Dlink ≫ Dir-836l Version -
Trendnet ≫ Tew-731br Firmware Version 2.01 Update b01
   Trendnet ≫ Tew-731br Version -
Dlink ≫ Dir-651 Firmware Version 1.10na Update b02
   Dlink ≫ Dir-651 Version -
Trendnet ≫ Tew-651br Firmware Version -
   Trendnet ≫ Tew-651br Version -
Trendnet ≫ Tew-652br Firmware Version -
   Trendnet ≫ Tew-652br Version -
Trendnet ≫ Tew-711br Firmware Version 1.00 Update b31
   Trendnet ≫ Tew-711br Version -
Trendnet ≫ Tew-810dr Firmware Version 1.00 Update b19
   Trendnet ≫ Tew-810dr Version -
Trendnet ≫ Tew-813dru Firmware Version 1.00 Update b23
   Trendnet ≫ Tew-813dru Version -

25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

Schwachstelle

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

Beschreibung

The impacted product is end-of-life and should be disconnected if still in use.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 82.86% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://packetstormsecurity.com/files/130607/D-Link-DIR636L-Remote-Command-Injection.html
Third Party Advisory
VDB Entry
Issue Tracking
http://packetstormsecurity.com/files/131465/D-Link-TRENDnet-NCC-Service-Command-Injection.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2015/Mar/15
Third Party Advisory
Mailing List
Issue Tracking
http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10052
Vendor Advisory
http://www.securityfocus.com/bid/72848
Third Party Advisory
Broken Link
VDB Entry
https://github.com/darkarnium/secpub/tree/master/Multivendor/ncc2
Third Party Advisory
Broken Link
Issue Tracking
Mitigation
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1187
US Government Resource