CVE-2026-2152General(dlink / dir-615)

MEDIUMCVSS 7.3 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dlink dir-615 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ submask/ gw results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-615
  • dir-615_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dir-615dir-615_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-08: 2Mentions · 2026-03-09: 1PoC Mentioned / Linked · 2026-02-08: 1Active Exploitation · 2026-02-08: 1Technical Details · 2026-02-08: 102-0803-09
Signal classification2 categories
General
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-082
Active Exploitation1General1
2026-03-091
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-2152 A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Perf… https://www.cve.org/CVERecord?id=CVE-2026-2152

    Post summary

    The post announces CVE‑2026‑2152, a vulnerability in the D‑Link DIR‑615 router’s adv_routing.php component, but provides no additional exploitation, patch, or technical detail.

    00010248
    56.5K followersView on X
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. 🛠️ CVE-2026-2155 (CVSS: 7.2) 2. 🛠️ CVE-2026-2152 (CVSS: 7.2) 3. 🛠️ CVE-2026-2151 (CVSS: 7.2) 4. 🛠️ CVE-2026-2143 (CVSS: 7.2) 5. 🛠️ CVE-2026-2142 (CVSS: 7.2) #CyberSecurity #CVE #Infosec

    Post summary

    The post enumerates five recent CVEs with CVSS 7.2 scores but provides no further technical or mitigative information.

    0000042
    167 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Active Exploitation

    🚨 HIGH-severity OS command injection in D-Link DIR-615 (v4.10) lets attackers execute remote commands with no auth needed. Devices are unsupported & public exploits are live — isolate or replace ASAP! https://radar.offseq.com/threat/cve-2026-2152-os-command-injection-in-d-link... https://t.co/T6p3dpKuOd

    Post summary

    CVE‑2026‑2152 is a high‑severity OS command injection vulnerability in D‑Link DIR‑615 that allows unauthenticated remote command execution, and public exploits are currently active; devices should be isolated or replaced immediately.

    0000036
    268 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-615---
OSdlinkdir-615_firmware4.10--

Explore more