Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-15194

Опубликовано: 29 дек. 2025
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dlink:dir-600_firmware:2.15ww:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-600:b2:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00136
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
github
около 1 месяца назад

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость функции sess_get_uid() микропрограммного обеспечения маршрутизаторов D-Link DIR-600, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 34%
0.00136
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-119