CVE-2014-100005 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities in D-Link DIR-600 (rev. Bx) routers with firmware older than 2.17b02. These flaws allow remote attackers to hijack administrator sessions to create new admin accounts, enable remote management, activate new settings, or send pings. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to complete compromise of the router. This CVE is actively exploited, listed in CISA's KEV catalog, and has a Metasploit module available, indicating significant community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.16wwCPE matchmatch criteria | cpe:2.3:o:dlink:dir-600_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.