CVE-2026-5815Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-09); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-04-08: 2Mentions · 2026-04-09: 4Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-04-09: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 4Technical Details · 2026-04-18: 104-0804-0904-18
Signal classification3 categories
Disclosure
571.4%
General
114.3%
PoC
114.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure2
2026-04-094
Disclosure2General1PoC1
2026-04-181
Disclosure1
Full discourse7 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5815 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5815 #CVE-2026-5815 #CVE #High #CyberSecurity #InfoSec https://t.co/4Vs0GmI4GX

    Post summary

    The tweet alerts to the new CVE-2026-5815 with severity 8.8, high risk across multiple products, and directs readers to the NVD page.

    0000142
    123 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    ```json { "x": "🚨 HIGH: CVE-2026-5815 (CVSS 8.8) - Stack-based buffer overflow in D-Link DIR-645 routers (v1.01-1.03). Remote exploit now PUBLIC. Devices are EOL - replace immediately. https://t.co/i0gsHXirPB

    Post summary

    The tweet announces a newly disclosed stack‑based buffer overflow in certain D‑Link routers, noting its severity and that a remote exploit is now publicly available, but it does not provide a PoC, exploit code, or evidence of active attacks.

    0000048
    25 followersView on X
  • dbugs@ptdbugs
    PoC

    D-Link DIR-645 hedwig.cgi hedwigcgi_main stack-based overflow CVE: CVE-2026-5815 PT ID: PT-2026-31448 Vendor: D-link Product: DIR-645 CVSS: 8.7 Credits: Pers1st (VulDB User) Description: A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5815 • https://vuldb.com/vuln/356263 • https://vuldb.com/vuln/356263/cti • https://vuldb.com/submit/788298 • https://github.com/Pers1st0/CVE/blob/main/stack-based%20buffer%20overflow%20vulnerability%20exists%20in%20the%20hedwig.cgi%20of%20D-Link%20DIR-645.md • https://github.com/Pers1st0/CVE/blob/main/stack-based%20buffer%20overflow%20vulnerability%20exists%20in%20the%20hedwig.cgi%20of%20D-Link%20DIR-645.md#poc • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The entry discloses a remote stack buffer overflow in D‑Link DIR‑645's hedwig.cgi, shares a public PoC via GitHub, and provides vulnerability metrics, but offers no patch information.

    0000090
    788 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5815: HIGH] Critical vulnerability in D-Link DIR-645 identified. Exploit allows remote stack-based buffer overflow attack through hedwig.cgi. Only unsupported products impacted.#cve,CVE-2026-5815,#cybersecurity https://cvefind.com/CVE-2026-5815

    Post summary

    The post announces CVE-2026‑5815, a high‑severity stack‑based buffer overflow vulnerability in the D‑Link DIR‑645, detailing the attack vector and affected devices, but provides no PoC, exploit code, or mitigation information.

    0000047
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5815 A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stac… https://www.cve.org/CVERecord?id=CVE-2026-5815 ----- Traducción: CVE-2026-5815 Se … http://infoflow.cloud`

    Post summary

    The post announces detection of CVE‑2026‑5815 affecting D‑Link DIR‑645 routers, citing the vulnerable function and implying a stack‑based issue, with a link to the CVE record.

    0000038
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5815 A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stac… https://www.cve.org/CVERecord?id=CVE-2026-5815

    Post summary

    The statement announces CVE‑2026‑5815 affecting D‑Link DIR‑645 models, specifying the vulnerable function and file but offers no PoC, exploit, or patch information.

    00000274
    57.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for D-Link DIR-645 (CVE-2026-5815) https://vuldb.com/vuln/356263

    Post summary

    A severe vulnerability (CVE-2026-5815) was disclosed for the D‑Link DIR‑645 router, but the post provides no technical details, PoC, exploit, or patch information.

    0000065
    2.1K followersView on X

Explore more