CVE-2014-100005: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
Other sources
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-100005?
CVE-2014-100005 is classified as a medium severity vulnerability due to its potential to enable unauthorized configuration changes.
How do I fix CVE-2014-100005?
To mitigate CVE-2014-100005, update the D-Link DIR-600 firmware to a version above 2.16ww.
What types of attacks can exploit CVE-2014-100005?
CVE-2014-100005 can be exploited through cross-site request forgery (CSRF) attacks that hijack an existing administrator session.
Who is affected by CVE-2014-100005?
Users of D-Link DIR-600 routers running firmware versions up to 2.16ww are affected by CVE-2014-100005.
What are the consequences of CVE-2014-100005?
CVE-2014-100005 allows attackers to change router configurations, potentially compromising network security.