VendorsD-Linkdir-600_firmwareall versions
Vulnerabilities

D-Link dir-600 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2013-10069
D-Link Devices Unauthenticated RCE
Published 2025-08-05 · Analyzed
10.0EPSS 0.119
CVE-2018-25115
D-Link DIR-110/412/600/615/645/815 RCE via service.cgi
Published 2025-08-27 · Analyzed
10.0EPSS 0.104
CVE-2025-15194
D-Link DIR-600 HTTP Header hedwig.cgi stack-based overflow
Published 2025-12-29 · Analyzed
10.0EPSS 0.012
CVE-2023-33625
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
Published 2023-06-12 · Modified
9.8EPSS 0.332
CVE-2013-7471
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.
Published 2019-06-11 · Modified
9.8EPSS 0.240
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
Published 2025-08-01 · Analyzed
9.8EPSS 0.171
CVE-2024-7357
D-Link DIR-600 soap.cgi soapcgi_main os command injection
Published 2024-08-01 · Analyzed
9.8EPSS 0.057
CVE-2023-33626
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.
Published 2023-06-12 · Modified
9.8EPSS 0.015
CVE-2014-100005
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Published 2015-01-13 · Analyzed
8.0KEVEPSS 0.435
CVE-2026-2163
D-Link DIR-600 ssdp.cgi command injection
Published 2026-02-08 · Analyzed
7.2EPSS 0.059