Vulnerability record · CVE-2015-2051 · published 23 February 2015
CVE-2015-2051: D-Link DIR-645 Router HNAP Command Injection
Dlink · Dir 645 Firmware
The D-Link DIR-645 wired/wireless router (Rev. Ax, firmware 1.04b12 and earlier) fails to sanitize input to the HNAP interface, allowing command injection through a GetDeviceSettings action. Because the flaw permits arbitrary command execution on the device, it exposes the router and everything behind it to full compromise.
Description
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, has public exploit code, is listed in CISA KEV, and carries a near-certain EPSS score, making it an urgent risk for any device still in service.
What it is
The D-Link DIR-645 wired/wireless router (Rev. Ax, firmware 1.04b12 and earlier) fails to sanitize input to the HNAP interface, allowing command injection through a GetDeviceSettings action. Because the flaw permits arbitrary command execution on the device, it exposes the router and everything behind it to full compromise.
Impact
An attacker can execute arbitrary commands on the router with the privileges of the affected service, gaining control of the device and a foothold on the network. This can lead to traffic interception, credential theft, and lateral movement into connected systems.
Attack surface
The vulnerability is reached over the network via the router's HNAP interface, which is exposed on the adjacent network segment per the CVSS vector (AV:A). No authentication or user interaction is required (PR:N, UI:N).
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS gives a 30-day exploitation probability of 0.971 (99.9th percentile). Public exploit code exists (Exploit-DB 37171), and the vendor advisory is tagged as an exploit reference.
What to do
- Apply the vendor firmware update if a supported version exists; otherwise replace the device, as the product is end-of-life.
- Disconnect or retire any D-Link DIR-645 still in use, per CISA's required action for this KEV entry.
- If the device cannot be removed immediately, isolate it on a dedicated network segment and block HNAP access from untrusted networks.
- Disable remote administration and UPnP on the router where possible to reduce exposure.
- Monitor for and block outbound connections from the router to unknown external hosts.
Detection
- Inspect network traffic for HNAP requests containing GetDeviceSettings actions with shell metacharacters or unexpected command strings.
- Monitor router logs and network flows for anomalous outbound connections originating from the device.
- Use an asset inventory to identify any D-Link DIR-645 devices still active on the network and flag them for remediation.
- Watch for signs of router configuration changes, new admin accounts, or DNS settings modifications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-2051 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "D-Link DIR-645 Router Remote Code Execution Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 10 August 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10051 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/72623 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/74870 | Broken LinkThird Party AdvisoryVDB Entry |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10282 | Vendor Advisory |
| https://www.exploit-db.com/exploits/37171/ | ExploitThird Party AdvisoryVDB Entry |
| http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10051 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/72623 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/74870 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/37171/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2051 | US Government Resource |
Track CVE-2015-2051 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2051), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.