LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2014-100005: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 16, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 6, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2014-100005 to its Known Exploited Vulnerabilities catalog on May 16, 2024, with a federal patch deadline of Jun 6, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.

CVE-2014-100005 is a cross-site request forgery vulnerability in D-Link DIR-600 routers. It allows an attacker to change router configurations by hijacking an existing administrator session. This matters because successful abuse can alter network settings, potentially enabling further unauthorized access or disruption on devices that sit at the edge of many small networks.

The issue affects legacy D-Link hardware that has reached end-of-life or end-of-service status. Defenders should treat it as a high-priority inventory and retirement item rather than a routine patch exercise.

How it works

The flaw belongs to CWE-352, cross-site request forgery. In this class of weakness, a web application fails to verify that state-changing requests originate from a legitimate user action rather than from a forged request crafted by an attacker. For the D-Link DIR-600, the CISA summary states that an attacker can change router configurations by hijacking an existing administrator session.

In practical terms, if an administrator is already authenticated to the router’s management interface, a malicious page or other content the administrator visits can cause the browser to issue configuration-changing requests that the router accepts as valid. Exact request formats, parameters, or attack vectors are not detailed in the provided facts; confirm any technical specifics against the vendor advisory. The result is unauthorized modification of router settings without the administrator deliberately submitting those changes.

Am I affected? How to find it in your systems

The vulnerability is documented only for the D-Link DIR-600 router. These devices commonly appear in home, small-office, or branch networks as consumer-grade wireless gateways. They are no longer supported; all associated hardware revisions have reached end-of-life or end-of-service.

Log or telemetry signs of exploitation are not specified in the facts. Monitor for unexpected configuration changes, new administrative accounts, altered DNS or firewall rules, or sudden reboots that coincide with administrator browser activity. Absent specific indicators, rely on configuration baselines and change-detection rather than signature hunting.

How to remediate

CISA’s required action is clear: this vulnerability affects legacy D-Link products whose hardware revisions have reached end-of-life or end-of-service. Retire and replace the devices per vendor instructions. No ongoing firmware support is expected.

If any vendor-supplied update or mitigation note still exists for residual units, apply it only after confirming applicability against the official advisory; do not assume a patch is available for EOL hardware.

If you can't patch immediately

Because the product is end-of-life, “patching” is not a realistic option. Focus on compensating controls that reduce exposure until replacement can be completed.

These measures lower the likelihood of successful CSRF abuse but do not eliminate the underlying weakness; replacement remains the only durable fix.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to broader network compromise and data exposure once an attacker gains control of the router. Known ransomware use is not documented for this CVE. If you suspect the device was abused, treat any credentials, traffic, or systems that traversed it as potentially compromised: rotate passwords, review connected hosts for secondary compromise, and examine logs for lateral movement. Readers can run a free exposure scan of their email addresses against known breach data sets to check whether related accounts appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DIR-600 Router
WeaknessCWE-352
Added to CISA KEVMay 16, 2024
Federal patch deadlineJun 6, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities