CVE-2015-1187: D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the pingaddr parameter to ping.ccp.
Other sources
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect any affected end-of-life D-Link and TRENDnet devices that are still in use to prevent remote attackers exploiting the ping tool via the ping_addr parameter to ping.ccp.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1187?
CVE-2015-1187 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2015-1187?
To fix CVE-2015-1187, update the firmware of the affected D-Link and TRENDnet devices to the latest version.
Which devices are affected by CVE-2015-1187?
CVE-2015-1187 affects multiple D-Link and TRENDnet devices, including specific models like DIR-626L, DIR-636L, DIR-808L, DIR-810L, and others.
What kind of attack does CVE-2015-1187 enable?
CVE-2015-1187 enables remote attackers to execute arbitrary code on vulnerable devices.
Is CVE-2015-1187 under active exploitation?
There have been reports of CVE-2015-1187 being exploited in the wild, emphasizing the importance of remediation.