CVE-2026-2151
7.2D-Link · DIR-615
A remote OS command injection vulnerability exists in the D-Link DIR-615 router due to improper input validation in the dmz_ipaddr argument within the DMZ Host Feature.
Executive summary
A critical OS command injection vulnerability in the D-Link DIR-615 router allows remote attackers to execute arbitrary commands with high privileges.
Vulnerability
This vulnerability involves OS command injection (CWE-78) within the adv_firewall.php component. An attacker with high privileges can manipulate the dmz_ipaddr parameter to inject and execute unauthorized operating system commands remotely.
Business impact
The exploitation of this vulnerability allows for full system compromise, enabling an attacker to gain unauthorized control over the affected network device. Given the CVSS score of 7.2, this represents a high risk to network integrity and confidentiality. Because the affected product is identified as end of life and no longer supported, the risk of permanent exposure to this flaw is significant.
Remediation
Immediate Action: As the product is no longer supported by the vendor, users should immediately decommission the affected D-Link DIR-615 hardware and replace it with a currently supported device.
Proactive Monitoring: Review system logs for suspicious activity involving the DMZ Host configuration or anomalous HTTP requests directed at the adv_firewall.php endpoint.
Compensating Controls: If immediate replacement is not feasible, isolate the device from the public internet using a restrictive firewall policy or a secondary gateway to limit the reach of potential remote attackers.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided by the researcher at the referenced Notion URL.
Analyst recommendation
The presence of a public proof-of-concept combined with the end-of-life status of the D-Link DIR-615 makes this a high-priority risk. Organizations currently utilizing this device should prioritize its removal from the network environment to prevent potential unauthorized access and compromise of internal network segments.
More D-Link CVEs
Sources
Originally found and disclosed by Zephyr369 (VulDB User), per the CVE Program record.
- VDB-344853 | D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection Vulnerability database entry
- VDB-344853 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #748031 | Dlink DIR-615 v4.10 OS Command Injection Third-party advisory
- Exploit / PoC
- dlink.com