CVE-2015-2051

CVE Published 2015-02-23
Related CWE(s) CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Related Vendor(s) dlink
Related Product(s) dir-645_firmware
Exploitation Reported (CISA KEV) 2022-02-10
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector ADJACENT_NETWORK

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References