Impact
The vulnerability is an OS command injection flaw found in the adv_routing.php script of D‑Link DIR‑615 routers running firmware 4.10. By supplying crafted values for the destination IP, subnet mask, or gateway parameters via the web configuration interface, an attacker can cause the router to execute arbitrary operating‑system commands. This allows full compromise of the device, giving the attacker control over routing tables, firewall rules, and potentially enabling further network attacks. The weakness corresponds to CWE‑77 and CWE‑78.
Affected Systems
The flaw affects D‑Link DIR‑615 routers with firmware version 4.10, a model that is no longer supported by the vendor. Only the DIR‑615 lineup is listed as impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. With an EPSS probability of 5 percent, the risk of exploitation is moderate to high in environments where the router is reachable from the Internet. The description states the attack may be initiated remotely via the web interface; it does not specify whether authentication is required, so the privilege level remains uncertain. The vulnerability is not listed in the CISA KEV catalog, but the public availability of an exploit increases real‑world risk.
OpenCVE Enrichment