LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-1187: D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-1187 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

CVE-2015-1187 is a remote code execution vulnerability affecting multiple D-Link and TRENDnet devices. It centers on the ping tool and improper authentication (CWE-287), allowing remote attackers to execute code on vulnerable units. Because these products are end-of-life, continued use leaves networks exposed to full device compromise; CISA advises disconnecting any still in service.

IT and security teams should treat this as a high-priority inventory and isolation issue rather than a routine patch cycle. Confirm all device-specific details against the original vendor advisories, as public records list only the broad product class and weakness.

How it works

The vulnerability belongs to CWE-287, improper authentication. On affected D-Link and TRENDnet devices the ping tool fails to enforce adequate authentication checks. An unauthenticated remote attacker can abuse this interface to achieve remote code execution.

In practical terms, the attacker reaches the device’s management or diagnostic function that implements ping, bypasses or omits required credentials, and supplies input that the device then executes with elevated privileges. Exact request formats, parameters, or payloads are not detailed in the available facts; defenders must treat any unauthenticated access to the ping facility as potentially sufficient for code execution and must verify behavior against the vendor advisory for each model.

Am I affected? How to find it in your systems

These devices commonly appear as consumer or small-office routers, access points, and related network appliances. They may still be present in branch offices, labs, IoT segments, or forgotten network closets.

How to remediate

The definitive remediation is removal. CISA states the impacted product is end-of-life and should be disconnected if still in use. Replace the hardware with a currently supported model from a vendor that still issues security updates.

No vendor patch is expected for end-of-life equipment; do not rely on firmware updates that may no longer be published.

If you can't patch immediately

When immediate disconnection is operationally impossible, apply compensating controls to shrink the attack surface until the device can be retired.

These measures only buy time; schedule permanent replacement as soon as possible.

If your data may have been exposed

Actively exploited remote-code-execution flaws on network devices frequently lead to credential theft, lateral movement, and data exfiltration. Although ransomware use is not documented for this CVE, treat any confirmed compromise as a potential breach. Rotate credentials, examine traffic logs for exfiltration, and consider a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link and TRENDnet · Multiple Devices
WeaknessCWE-287
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities