CVE-2015-1187: D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

Published Sep 21, 2017
·
Updated

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the pingaddr parameter to ping.ccp.

Other sources

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

CISA

Affected Software

70 affected components
D-Link and TRENDnet Multiple Devices
D-Link Dir-626l Firmware=1.04-b04
Dlink Dir-626l
D-Link Dir-636l Firmware=1.04
Dlink Dir-636l
D-Link Dir-808l Firmware=1.03-b05
Dlink Dir-808l
D-Link Dir-810l Firmware=1.01-b04
Dlink Dir-810l
D-Link Dir-810l Firmware=2.02-b01
D-Link Dir-820l Firmware=1.02-b10
Dlink Dir-820l
D-Link Dir-820l Firmware=1.05-b03
D-Link Dir-820l Firmware=2.01-b02
D-Link Dir-826l Firmware=1.00-b23
Dlink Dir-826l
D-Link Dir-830l Firmware=1.00-b07
Dlink Dir-830l
D-Link Dir-836l Firmware=1.01-b03
Dlink Dir-836l
Trendnet Tew-731br Firmware=2.01-b01
Trendnet Tew-731br
D-Link Dir-651 Firmware=1.10na-b02
Dlink Dir-651
Trendnet Tew-651br Firmware
Trendnet TEW-651BR
Trendnet Tew-652br Firmware
Trendnet Tew-652br
Trendnet Tew-711br Firmware=1.00-b31
Trendnet Tew-711br
Trendnet Tew-810dr Firmware=1.00-b19
Trendnet Tew-810dr
Trendnet Tew-813dru Firmware=1.00-b23
Trendnet Tew-813dru
All of the following
Dlink Dir-626l Firmware=1.04-b04
Dlink Dir-626l
All of the following
Dlink Dir-636l Firmware=1.04
Dlink Dir-636l
All of the following
Dlink Dir-808l Firmware=1.03-b05
Dlink Dir-808l
All of the following
Dlink Dir-810l Firmware=1.01-b04
Dlink Dir-810l
All of the following
Dlink Dir-810l Firmware=2.02-b01
Dlink Dir-810l
All of the following
Dlink Dir-820l Firmware=1.02-b10
Dlink Dir-820l
All of the following
Dlink Dir-820l Firmware=1.05-b03
Dlink Dir-820l
All of the following
Dlink Dir-820l Firmware=2.01-b02
Dlink Dir-820l
All of the following
Dlink Dir-826l Firmware=1.00-b23
Dlink Dir-826l
All of the following
Dlink Dir-830l Firmware=1.00-b07
Dlink Dir-830l
All of the following
Dlink Dir-836l Firmware=1.01-b03
Dlink Dir-836l
All of the following
Trendnet Tew-731br Firmware=2.01-b01
Trendnet Tew-731br
All of the following
Dlink Dir-651 Firmware=1.10na-b02
Dlink Dir-651
All of the following
Trendnet Tew-651br Firmware
Trendnet TEW-651BR
All of the following
Trendnet Tew-652br Firmware
Trendnet Tew-652br
All of the following
Trendnet Tew-711br Firmware=1.00-b31
Trendnet Tew-711br
All of the following
Trendnet Tew-810dr Firmware=1.00-b19
Trendnet Tew-810dr
All of the following
Trendnet Tew-813dru Firmware=1.00-b23
Trendnet Tew-813dru

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Disconnect any affected end-of-life D-Link and TRENDnet devices that are still in use to prevent remote attackers exploiting the ping tool via the ping_addr parameter to ping.ccp.

Event History

Sep 21, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Mar 25, 2022
Known Exploited
via CISA·12:00 AM
Feb 28, 58274
Event
via NVD·10:56 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-1187?

CVE-2015-1187 has a high severity rating due to its potential for remote code execution.

2

How do I fix CVE-2015-1187?

To fix CVE-2015-1187, update the firmware of the affected D-Link and TRENDnet devices to the latest version.

3

Which devices are affected by CVE-2015-1187?

CVE-2015-1187 affects multiple D-Link and TRENDnet devices, including specific models like DIR-626L, DIR-636L, DIR-808L, DIR-810L, and others.

4

What kind of attack does CVE-2015-1187 enable?

CVE-2015-1187 enables remote attackers to execute arbitrary code on vulnerable devices.

5

Is CVE-2015-1187 under active exploitation?

There have been reports of CVE-2015-1187 being exploited in the wild, emphasizing the importance of remediation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203