Vulnerability Description
A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-600 Firmware | 2.15ww |
| Dlink | Dir-600 | b2 |
Related Weaknesses (CWE)
References
- https://github.com/LonTan0/CVE/blob/main/Stack-Based%20Buffer%20Overflow%20VulneExploitThird Party Advisory
- https://github.com/LonTan0/CVE/blob/main/Stack-Based%20Buffer%20Overflow%20VulneExploitThird Party Advisory
- https://vuldb.com/?ctiid.338581Permissions RequiredVDB Entry
- https://vuldb.com/?id.338581Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.724404Third Party AdvisoryVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2025-15194?
CVE-2025-15194 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of...
How severe is CVE-2025-15194?
CVE-2025-15194 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-15194?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-600 Firmware, Dlink Dir-600.