CVE-2026-1505
7.2D-Link · DIR-615
A remote OS command injection vulnerability exists in D-Link DIR-615 version 4.10 within the URL Filter component's /set_temp_nodes.php file.
Executive summary
An OS command injection vulnerability in D-Link DIR-615 version 4.10 allows remote attackers with administrative privileges to execute arbitrary commands, posing a severe risk to device integrity.
Vulnerability
This vulnerability involves an OS command injection flaw located in the /set_temp_nodes.php file. The vulnerability is exploitable remotely by an authenticated user with administrative privileges who can manipulate parameters to execute arbitrary operating system commands.
Business impact
The exploitation of this vulnerability could lead to a complete compromise of the affected router, potentially allowing attackers to pivot into the internal network, intercept traffic, or exfiltrate sensitive data. Given the CVSS score of 7.2, this represents a high-severity risk, especially considering that the product is no longer supported by the vendor, meaning official security patches are unlikely to be released.
Remediation
Immediate Action: Since the product is end-of-life and no official patch is available, the primary remediation is to retire and replace the affected D-Link DIR-615 hardware with currently supported equipment.
Proactive Monitoring: Monitor firewall logs for unusual outbound traffic or unauthorized access attempts directed at the /set_temp_nodes.php endpoint.
Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses only, and implement strict network segmentation to minimize potential lateral movement if the device is compromised.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced security research write-up.
Analyst recommendation
The severity of this flaw, combined with the end-of-life status of the D-Link DIR-615, presents an unacceptable security risk to any network environment. Organizations must prioritize the decommissioning of these devices immediately, as no vendor-provided remediation is forthcoming to address this command injection vulnerability.
More D-Link CVEs
Sources
Originally found and disclosed by Zephyr369 (VulDB User), per the CVE Program record.
- VDB-343117 | D-Link DIR-615 URL Filter set_temp_nodes.php os command injection Vulnerability database entry
- VDB-343117 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #737061 | Dlink DIR-615 v4.10 OS Command Injection Third-party advisory
- Exploit / PoC
- dlink.com