CVE-2015-2051
dlink dir-645, dlink dir-645_firmware
Published 23 Feb 2015 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Feb 2022, with a remediation deadline of 10 Aug 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
References
- securityadvisories.dlink.com/security/publication.aspx?name=SAP10051 · Exploit, Vendor Advisory
- www.securityfocus.com/bid/72623 · Broken Link, Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/74870 · Broken Link, Third Party Advisory, VDB Entry
- supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10282 · Vendor Advisory
- www.exploit-db.com/exploits/37171/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2051 · US Government Resource