CVE-2014-100005 Details
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-100005 | CISA-ADP | US Government Resource |
| http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/ | CVE | ExploitThird Party Advisory |
| http://secunia.com/advisories/57304 | CVE | Broken Link |
| http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018 | CVE | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/91794 | CVE | Third Party AdvisoryVDB Entry |
| http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/ | [email protected] | ExploitThird Party Advisory |
| http://secunia.com/advisories/57304 | [email protected] | Broken Link |
| http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018 | [email protected] | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/91794 | [email protected] | Third Party AdvisoryVDB Entry |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | May 16, 2024 | Jun 6, 2024 | This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dlink dir-600 firmware | <= 2.16ww |
CPE
Remediation
| |
| dlink dir-600 | All versions |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Dec 20, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 13, 2024 | Modified Analysis | [email protected] |
| Aug 1, 2024 | CVE Modified | CISA-ADP |
| May 18, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 8, 2023 | Modified Analysis | [email protected] |
| Sep 8, 2017 | CVE Modified | [email protected] |
| Jan 13, 2015 | Modified Analysis | [email protected] |
| Jan 13, 2015 | Initial Analysis | [email protected] |