Dir 645
Vendor:
First CVE: Jul 7, 2014 · Active for 12 years
12
Total CVEs
More Total CVEs than 90% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 82% of tracked products
8.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dir 645 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2014
12 years ago
Most Recent CVE
Sep 18, 2025
310 days ago
CVE Severity & Scoring
Dir 64512 CVEs
17%
25%
58%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (83.3%)
Unknown2 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High0 (0.0%)
Unknown2 (16.7%)
User Interaction
None9 (75.0%)
Unknown2 (16.7%)
Required1 (8.3%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None9 (75.0%)
Unknown2 (16.7%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2051HIGH The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP | Feb 23, 2015 | 8.8 | 98 | YES | YES |
CVE-2013-7389MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML vi | Jul 7, 2014 | 4.3 | 47 | NO | YES |
CVE-2013-7471CRITICAL An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. The | Jun 11, 2019 | 9.8 | 44 | NO | NO |
CVE-2022-46475CRITICAL D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function. | Jan 17, 2023 | 9.8 | 35 | NO | NO |
CVE-2018-25115CRITICAL Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi en | Aug 27, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10689CRITICAL A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to comm | Sep 18, 2025 | 9.8 | 33 | NO | NO |
CVE-2022-32092CRITICAL D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi. | Jun 27, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-43722CRITICAL D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit o | Mar 31, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-36089CRITICAL Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vuln | Jul 31, 2023 | 9.8 | 30 | NO | NO |
CVE-2015-2052HIGH Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a | Feb 23, 2015 | 10.0 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
1 CVE
8.3% of CVEs· 97th percentile
Metasploit
2 CVEs
16.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Dir 645
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| a1 | 1 | 4.3 | 27.8% | 0 | 1 |