CVE-2026-5815: D-Link DIR-645 hedwig.cgi hedwigcgi_main stack-based overflow
A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgimain of the file /cgi-bin/hedwig.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
Which device versions are affected?
D-Link DIR-645 devices running versions 1.01, 1.02, or 1.03 are identified as affected.
What access does an attacker need to exploit this issue?
The attack can be launched remotely. The CVSS vector indicates low privileges are required and no user interaction is required.
Is exploit code publicly available?
A public exploit is available, so the vulnerability may be used by attackers.
What is the vendor support status and are mitigations documented?
The affected products are no longer supported by the maintainer. No workaround or patch information is provided in the available data.