← Vulnerability feed

Vulnerability record · CVE-2018-15839 · published 28 August 2018

CVE-2018-15839: D-Link DIR-615 router buffer overflow via long Authorization header

Dlink · Dir 615 Firmware

D-Link DIR-615 firmware contains a memory buffer overflow (CWE-119) triggered by an overly long Authorization HTTP header. The flaw is remotely reachable over the network with no privileges or user interaction required, and the CVSS 3.1 base score is 9.8 (critical). Successful exploitation can corrupt memory and potentially allow code execution or denial of service on the affected device.

9.8 CVSS 3.1 Critical EPSS 45% · top 1.2% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 7.5
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and public exploit code make this a high-risk unauthenticated remote flaw.

What it is

D-Link DIR-615 firmware contains a memory buffer overflow (CWE-119) triggered by an overly long Authorization HTTP header. The flaw is remotely reachable over the network with no privileges or user interaction required, and the CVSS 3.1 base score is 9.8 (critical). Successful exploitation can corrupt memory and potentially allow code execution or denial of service on the affected device.

Impact

An unauthenticated remote attacker can overflow a buffer in the router's HTTP handling, which may lead to arbitrary code execution or a crash/denial of service. Full compromise of confidentiality, integrity and availability is scored by the CVSS vector.

Attack surface

Reached over the network via HTTP by sending a crafted Authorization header to the DIR-615 web interface; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication or user interaction is needed. The description does not specify which firmware versions or interface paths are affected.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.45347, ~98.7th percentile) and public exploit code exists on Exploit-DB (45317), indicating practical exploitation is feasible. No ransomware association is documented.

What to do

  • Apply the latest D-Link firmware for DIR-615 or replace the device if no fixed firmware is available; the record does not list a specific patched version.
  • Disable remote/WAN administration and restrict the web interface to trusted management networks only.
  • Place the device behind a firewall or reverse proxy that filters or normalizes oversized HTTP headers.
  • Monitor vendor advisories for DIR-615 and retire end-of-support units that will not receive fixes.

Detection

  • Inspect HTTP request logs or IDS/IPS signatures for abnormally long Authorization headers targeting the router web interface.
  • Alert on crashes, reboots or unexpected process restarts of the DIR-615 management service.
  • Watch for exploit traffic matching Exploit-DB 45317 patterns against D-Link management ports.
  • Baseline normal Authorization header lengths and flag outliers from external or untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15839 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2014-8361Realtek SDK miniigd SOAP service remote code executionThe miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw…KEVEPSS 100%analysed10.0CVE-2018-25115Dlink dir-110 firmware os command injection vulnerabilityMultiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…EPSS 10%9.8CVE-2021-42627D-Link DIR-615 WAN page exposed without authenticationThe WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated …EPSS 63%analysed9.8CVE-2021-37388Dlink dir-615 firmware classic buffer overflow vulnerabilityA buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver …EPSS 3.7%8.8CVE-2019-17525Dlink dir-615 firmware improper restriction of authentication attempts vulnerabilityThe login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.EPSS 5.8%8.7CVE-2013-10050Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authentica…EPSS 14%8.2CVE-2019-17353Dlink dir-615 firmware missing authentication for critical function vulnerabilityAn issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which c…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2018-15839), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.