CVE-2015-2051 is a critical command injection vulnerability affecting D-Link DIR-645 Wired/Wireless Routers with firmware 1.04b12 and earlier. This flaw allows remote, unauthenticated attackers to execute arbitrary commands on the device by sending a specially crafted request to the HNAP interface. With a CVSS score of 9.8, this vulnerability poses a severe risk, enabling complete compromise of the affected router. The vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog and recent reports of botnets like "Goldoon" and "Moobot" leveraging it. Exploit code is publicly available, including a Metasploit module, making it easily weaponizable. The high EPSS score and extensive community discussion and media coverage further underscore its widespread awareness and exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.05b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-645_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.