Dir 600
Vendor:
First CVE: Jan 13, 2015 · Active for 11 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
9.4
Avg CVSS
Higher Avg CVSS than 87% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dir 600 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2015
11 years ago
Most Recent CVE
Feb 8, 2026
167 days ago
CVE Severity & Scoring
Dir 60010 CVEs
20%
80%
All CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low0 (0.0%)
High1 (10.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-100005HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of ad | Jan 13, 2015 | 8.0 | 90 | YES | YES |
CVE-2023-33625CRITICAL D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function. | Jun 12, 2023 | 9.8 | 57 | NO | YES |
CVE-2013-10048CRITICAL An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper inpu | Aug 1, 2025 | 9.8 | 49 | NO | YES |
CVE-2013-10069CRITICAL The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in comman | Aug 5, 2025 | 9.8 | 48 | NO | YES |
CVE-2013-7471CRITICAL An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. The | Jun 11, 2019 | 9.8 | 44 | NO | NO |
CVE-2018-25115CRITICAL Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi en | Aug 27, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-15194CRITICAL A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. | Dec 29, 2025 | 9.8 | 33 | NO | NO |
CVE-2023-33626CRITICAL D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary. | Jun 12, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-7357CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the function soapcgi_main of the file /soa | Aug 1, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-2163HIGH A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADD | Feb 8, 2026 | 7.2 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
1 CVE
10.0% of CVEs· 97th percentile
Metasploit
4 CVEs
40.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Dir 600
Top CWEs
Versions
No cataloged versions.