CVE-2014-100005
published 2015-01-13CVE-2014-100005: Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the…
PriorityP279high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-06-06
Exploited in the wild
EPSS
47.07%
98.7th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-600_firmware | <= 2.16ww | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-LINK Router DIR-645 / DIR-815 RCE (CVE-2014-100005)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/diagnostic.php"; fast_pattern; endswith; http.request_body; content:"act=ping"; content:"dst="; pcre:"/^(?:\x3b|\x0a|\x26|\x60|\x7C|\x24)/R"; reference:cve,2014-100005; reference:url,raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dlink_diagnostic_exec_noauth.rb; classtype:attempted-admin; sid:2052885; rev:2; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state TLSDecrypt, created_at 2024_05_24, cve CVE_2014_100005, deployment Perimeter, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_05_30, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
- →Detect POST requests to /diagnostic.php with body containing 'act=ping' and 'dst=' followed by shell metacharacters (;, newline, &, backtick, |, $) — indicative of OS command injection exploitation of the CSRF/RCE chain.
- →Monitor for POST requests to /hedwig.cgi with crafted configuration modules, which can be used to create rogue administrator accounts or enable remote management via CSRF. ↗
- →Monitor for POST requests to /pigwidgeon.cgi with a SETCFG,SAVE,ACTIVATE action, which activates new (attacker-controlled) configuration settings on the router. ↗
- →Older vulnerabilities like this are typically leveraged by botnet malware; correlate exploitation attempts against D-Link DIR-600 with known botnet C2 infrastructure. ↗
- ·The Snort/ET rule is misattributed in its msg field — it references DIR-645/DIR-815 RCE but the CVE (CVE-2014-100005) is assigned to the D-Link DIR-600 CSRF vulnerability. Analysts should be aware the rule covers the /diagnostic.php command injection vector, which is related but distinct from the core CSRF issue.
- ·The vulnerability affects D-Link DIR-600 (rev. Bx) with firmware before 2.17b02. All associated hardware revisions have reached EOL/EOS and the vendor recommends device replacement rather than patching. ↗
- ·On DIR-645 versions prior to 1.03, authentication is not required to exploit the /diagnostic.php command injection; on version 1.03 authentication is needed; the vulnerability was fixed in version 1.04. Detection rules should account for both authenticated and unauthenticated request patterns. ↗
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ppfw-543c-9q84: Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev
ghsa_unreviewed·2022-05-17
CVE-2014-100005 [MEDIUM] CWE-352 GHSA-ppfw-543c-9q84: Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
VulnCheck
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
vulncheck·2014·CVSS 8.8
CVE-2014-100005 [HIGH] CWE-352 D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
Affected: D-Link DIR-600 Router
Required Action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.fortiguard.com/outbreak-alert/d-link-multiple-devices-attack; https://www.forescout.com/resources/2024h1-threat-review/
Remediation Due: 2024-06-06
CISA
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
cisa·2024-05-16·CVSS 8.8
CVE-2014-100005 [HIGH] CWE-352 D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
Vulnerability: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
Affected: D-Link DIR-600 Router
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
Required Action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Notes: https://legacy.us.dlink.com/pages/product.aspx?id=4587b63118524aec911191cc81605283; https://nvd.nist.gov/vuln/detail/CVE-2014-100005
Remediation Due Date: 2024-06-06
Suricata
ET EXPLOIT D-LINK Router DIR-645 / DIR-815 RCE (CVE-2014-100005)
suricata·2024-05-24·CVSS 8.8
CVE-2014-100005 [HIGH] ET EXPLOIT D-LINK Router DIR-645 / DIR-815 RCE (CVE-2014-100005)
ET EXPLOIT D-LINK Router DIR-645 / DIR-815 RCE (CVE-2014-100005)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-LINK Router DIR-645 / DIR-815 RCE (CVE-2014-100005)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/diagnostic.php"; fast_pattern; endswith; http.request_body; content:"act=ping"; content:"dst="; pcre:"/^(?:\x3b|\x0a|\x26|\x60|\x7C|\x24)/R"; reference:cve,2014-100005; reference:url,raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dlink_diagnostic_exec_noauth.rb; classtype:attempted-admin; sid:2052885; rev:2; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state TLSDecrypt, created_at 2024_05_24, cve CVE_2014_100005, deployment Perimeter, confidence High, signature_sever
http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/http://secunia.com/advisories/57304http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018https://exchange.xforce.ibmcloud.com/vulnerabilities/91794http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/http://secunia.com/advisories/57304http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018https://exchange.xforce.ibmcloud.com/vulnerabilities/91794https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-100005
2015-01-13
Published
2024-05-16
Added to CISA KEV
Exploited in the wild