Vulnerability record · CVE-2015-1187 · published 21 September 2017
CVE-2015-1187: D-Link and TRENDnet ping tool command injection allows remote code execution
Dlink · Dir 626l Firmware
The ping tool in multiple D-Link and TRENDnet router and access point firmware fails to properly authenticate or sanitize the ping_addr parameter passed to ping.ccp, allowing command injection. Because the flaw is reachable over the network without credentials, it exposes affected devices to full remote code execution.
Description
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, KEV listing and near-maximum EPSS probability on end-of-life devices.
What it is
The ping tool in multiple D-Link and TRENDnet router and access point firmware fails to properly authenticate or sanitize the ping_addr parameter passed to ping.ccp, allowing command injection. Because the flaw is reachable over the network without credentials, it exposes affected devices to full remote code execution.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the device, gaining full control of confidentiality, integrity and availability. This can lead to router takeover, traffic interception and use of the device as a foothold in the network.
Attack surface
Reachable over the network via the ping.ccp endpoint and the ping_addr parameter; the CVSS vector shows no privileges or user interaction required. The CWE-287 classification indicates improper authentication on that interface.
Exploitation
CVE-2015-1187 is listed in CISA KEV with a 2022-03-25 addition date, and EPSS shows a 30-day probability of 0.82863 (99.65th percentile). Public exploit references are tagged Exploit, confirming working exploit code exists.
What to do
- Apply the vendor advisory SAP10052 fix if a supported firmware exists; otherwise treat the device as end-of-life.
- Per CISA KEV guidance, disconnect end-of-life affected D-Link and TRENDnet devices from the network.
- Block or restrict access to ping.ccp and the device management interface from untrusted networks.
- Replace affected models with supported hardware that receives security updates.
- Segment any remaining devices on an isolated management VLAN with no internet exposure.
Detection
- Monitor HTTP requests to ping.ccp with suspicious or shell metacharacter content in the ping_addr parameter.
- Alert on outbound connections or command execution activity originating from router and access point management IPs.
- Inventory D-Link and TRENDnet devices matching the affected firmware model list and flag any still reachable from untrusted networks.
- Review device logs for unexpected ping or diagnostic invocations and for authentication bypass patterns on the management interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-1187 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 April 2022.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1187 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1187), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.