CVE-2026-2163: D-Link DIR-600 ssdp.cgi command injection
A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTPST/REMOTEADDR/REMOTEPORT/SERVERID leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2163?
CVE-2026-2163 has a critical severity level due to its potential for command injection.
How do I fix CVE-2026-2163?
To fix CVE-2026-2163, update the D-Link DIR-600 firmware to a version later than 2.15WWb02.
What type of vulnerability is CVE-2026-2163?
CVE-2026-2163 is a command injection vulnerability affecting the ssdp.cgi file in D-Link DIR-600 devices.
What can attackers achieve with CVE-2026-2163?
Attackers can exploit CVE-2026-2163 to execute arbitrary commands on the affected D-Link DIR-600 device.
Which versions of D-Link DIR-600 are affected by CVE-2026-2163?
CVE-2026-2163 affects D-Link DIR-600 devices running firmware version up to and including 2.15WWb02.