cbcvebase.
CVE-2015-1187
published 2017-09-21

CVE-2015-1187: The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

Affected

16 ranges
VendorProductVersion rangeFixed in
dlinkdir-626l_firmware
dlinkdir-636l_firmware
dlinkdir-651_firmware
dlinkdir-808l_firmware
dlinkdir-810l_firmware
dlinkdir-810l_firmware
dlinkdir-820l_firmware
dlinkdir-820l_firmware
dlinkdir-820l_firmware
dlinkdir-826l_firmware
dlinkdir-830l_firmware
dlinkdir-836l_firmware
trendnettew-711br_firmware
trendnettew-731br_firmware
trendnettew-810dr_firmware
trendnettew-813dru_firmware

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL