CVE-2025-15194(dlink / dir-600)

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-600
  • dir-600_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
dir-600dir-600_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 CRITICAL: CVE-2025-15194 (CVSS 9.8) affects D-Link DIR-600 routers ≤2.15WWb02. Stack-based buffer overflow in hedwig[.]cgi via Cookie header. Exploit public. Products EOL—replace immediately. #CVE #PatchNow #ThreatIntel https://t.co/2ZJeMNycBo

    0000018
    142 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-600b2--
OSdlinkdir-600_firmware2.15ww--

Explore more