CVE-2015-1187 is a critical command injection vulnerability affecting D-Link and TRENDnet devices, allowing remote attackers to execute arbitrary code via the ping_addr parameter in the ping tool. With a CVSS score of 9.8, this vulnerability presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (confidentiality, integrity, availability). It is actively exploited in the wild, with public Metasploit modules available and significant community discussion, including its use by Mirai DDoS malware variants.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-626l_firmware:1.04:b04:*:*:*:*:*:* | ||
1.04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-636l_firmware:1.04:*:*:*:*:*:*:* | ||
1.03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-808l_firmware:1.03:b05:*:*:*:*:*:* | ||
1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-810l_firmware:1.01:b04:*:*:*:*:*:* | ||
2.02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-810l_firmware:2.02:b01:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.