LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-2051: D-Link DIR-645 Router Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-2051 to its Known Exploited Vulnerabilities catalog on Feb 10, 2022, with a federal patch deadline of Aug 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

CVE-2015-2051 is a remote code execution vulnerability in the D-Link DIR-645 wired/wireless router. It allows remote attackers to run arbitrary commands through the device’s HNAP interface via a GetDeviceSettings action. Because the product is end-of-life, any remaining units represent ongoing risk if still connected to a network.

For IT and security teams, this matters because a compromised router can give an attacker a foothold on the local network, enabling further lateral movement, traffic interception, or persistent access. Confirm all version and configuration details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-77 (command injection). In this class of flaw, user-controlled input reaches a command interpreter without proper sanitization or validation. On the DIR-645, the HNAP interface accepts a GetDeviceSettings action; an attacker who can reach that interface can supply crafted input that the device treats as operating-system commands.

Exploitation requires network access to the vulnerable HNAP endpoint. Once successful, the attacker can execute arbitrary commands with the privileges of the process handling HNAP requests. Exact request format, authentication requirements, and payload construction are not detailed here; treat any public proof-of-concept material cautiously and verify behavior only in isolated lab conditions against the vendor advisory.

Am I affected? How to find it in your systems

The affected product is the D-Link DIR-645 router. These devices commonly appear in small-office, home-office, and branch environments as the primary gateway or wireless access point. Inventory steps:

Because the product is end-of-life, assume any discovered DIR-645 is vulnerable unless the vendor advisory explicitly states otherwise. Telemetry signs of exploitation are generic for command-injection attacks on embedded devices: unexpected outbound connections from the router, unfamiliar processes or cron-like jobs if shell access is obtained, sudden configuration changes, or HNAP-related requests in packet captures that contain unusual parameter values. Enable logging on upstream firewalls and monitor for anomalous traffic originating from the router’s IP.

How to remediate

The CISA-required action is clear: the impacted product is end-of-life and should be disconnected if still in use. Replace the DIR-645 with a supported router that receives current security updates. After removal:

If a vendor patch or firmware update was ever published for this CVE, apply it only after confirming the exact fixed version in the official advisory; do not rely on third-party claims. For the broader command-injection class, harden remaining network devices by disabling unnecessary management services, restricting administrative interfaces to dedicated management networks, and enforcing strong authentication.

If you can't patch immediately

Immediate disconnection is the preferred control. When replacement cannot occur at once, apply these compensating measures:

These steps reduce exposure but do not eliminate the underlying command-injection risk. Schedule replacement as a priority.

If your data may have been exposed

Actively exploited router vulnerabilities can lead to network breaches, credential theft, or persistent access. If you suspect compromise, isolate the device, preserve logs, and begin incident-response procedures. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether associated credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DIR-645 Router
WeaknessCWE-77
Added to CISA KEVFeb 10, 2022
Federal patch deadlineAug 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities