← Back to browse · API

CVE-2014-100005

Severity
HIGH
CVSS
8.0
EPSS
0.42414
Risk score
71.84
CISA KEV
Yes
PoC
No
Published
2015-01-13
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2014-1036, GHSA-PPFW-543C-9Q84
Products
D-Link:DIR-600 Router, n/a:n/a n/a
Sources
cisa.gov CVE-2014-100005
euvd EUVD-2014-1036

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

References