CVE-2026-1505

7.2

D-Link · DIR-615

A remote OS command injection vulnerability exists in D-Link DIR-615 version 4.10 within the URL Filter component's /set_temp_nodes.php file.

Executive summary

An OS command injection vulnerability in D-Link DIR-615 version 4.10 allows remote attackers with administrative privileges to execute arbitrary commands, posing a severe risk to device integrity.

Vulnerability

This vulnerability involves an OS command injection flaw located in the /set_temp_nodes.php file. The vulnerability is exploitable remotely by an authenticated user with administrative privileges who can manipulate parameters to execute arbitrary operating system commands.

Business impact

The exploitation of this vulnerability could lead to a complete compromise of the affected router, potentially allowing attackers to pivot into the internal network, intercept traffic, or exfiltrate sensitive data. Given the CVSS score of 7.2, this represents a high-severity risk, especially considering that the product is no longer supported by the vendor, meaning official security patches are unlikely to be released.

Remediation

Immediate Action: Since the product is end-of-life and no official patch is available, the primary remediation is to retire and replace the affected D-Link DIR-615 hardware with currently supported equipment.

Proactive Monitoring: Monitor firewall logs for unusual outbound traffic or unauthorized access attempts directed at the /set_temp_nodes.php endpoint.

Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses only, and implement strict network segmentation to minimize potential lateral movement if the device is compromised.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced security research write-up.

Analyst recommendation

The severity of this flaw, combined with the end-of-life status of the D-Link DIR-615, presents an unacceptable security risk to any network environment. Organizations must prioritize the decommissioning of these devices immediately, as no vendor-provided remediation is forthcoming to address this command injection vulnerability.

More D-Link CVEs

Sources

Originally found and disclosed by Zephyr369 (VulDB User), per the CVE Program record.