Stack-Based Buffer Overflow in D-Link DIR-645 Routers
CVE-2026-5815
Key Information:
Badges
What is CVE-2026-5815?
A security vulnerability in the D-Link DIR-645 router's hedwigcgi_main function, located in the hedwig.cgi file, leads to a stack-based buffer overflow. This flaw can be exploited remotely, allowing unauthorized users to manipulate the system. The problem predominantly affects versions 1.01, 1.02, and 1.03 of the DIR-645, which are no longer maintained by D-Link. Immediate action is advised to mitigate potential threats from publicly available exploits.
Affected Version(s)
DIR-645 1.01
DIR-645 1.02
DIR-645 1.03
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved