CVE-2014-100005
CWE-352
92.4
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
Source: NVD
Signals
- CVSS
- 8.0
- High · v3.1
- EPSS
- 43.45%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since May 2024
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-352
- Published
- 13 Jan 2015
- Last modified 22 Apr 2026
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2014-100005Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time