CVE-2015-1187

CVE Published 2017-09-21
Related CWE(s) CWE-287: Improper Authentication
Related Vendor(s) dlink, trendnet
Related Product(s) dir-820l_firmware, dir-836l_firmware, dir-636l_firmware, tew-813dru_firmware, tew-651br_firmware, dir-808l_firmware, dir-651_firmware, tew-652br_firmware, tew-711br_firmware, dir-626l_firmware, dir-830l_firmware, tew-810dr_firmware, dir-810l_firmware, tew-731br_firmware, dir-826l_firmware
Exploitation Reported (CISA KEV) 2022-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References