CVE-2015-2051: D-Link DIR-645 Router Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-02-10. EPSS: 97.1% chance of exploitation in the next 30 days.

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

Affected products

  • D-Link DIR-645 Firmware: before 1.05b01 (fixed in 1.05b01)

Published 2015-02-23. Last modified 2026-06-17.