CVE-2026-2152
7.2D-Link · DIR-615
A remote OS command injection vulnerability exists in the D-Link DIR-615 web configuration interface, specifically within the adv_routing.php file via the dest_ip, submask, or gw parameters.
Executive summary
The D-Link DIR-615 router contains a critical OS command injection vulnerability that allows remote attackers to execute arbitrary commands on the device.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) located in the adv_routing.php file of the web configuration interface. An authenticated attacker with high privileges can trigger command execution by manipulating the dest_ip, submask, or gw arguments.
Business impact
Successful exploitation grants an attacker full control over the affected router, potentially allowing them to intercept network traffic, modify configuration settings, or use the device as a pivot point for lateral movement within the internal network. With a CVSS score of 7.2, this vulnerability represents a significant risk to network integrity and confidentiality. Because the device is no longer supported by the vendor, there is no expectation of an official security update to resolve this flaw.
Remediation
Immediate Action: Since the product is end-of-life and no patch will be provided, immediately retire and replace the affected D-Link DIR-615 hardware with a currently supported device.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from the router management interface and review administrative logs for suspicious parameter strings associated with routing configuration changes.
Compensating Controls: If the device cannot be immediately replaced, restrict access to the web management interface to a dedicated management VLAN or trusted IP addresses via firewall rules to prevent unauthorized remote access.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up referenced by the CVE record.
Analyst recommendation
Given that the D-Link DIR-615 is officially unsupported and this vulnerability allows for remote command execution, the risk of continued operation is extreme. Organizations must prioritize the decommissioning of these devices, as no vendor-supplied patch is forthcoming to remediate the underlying security flaw.
More D-Link CVEs
Sources
Originally found and disclosed by Zephyr369 (VulDB User), per the CVE Program record.
- VDB-344854 | D-Link DIR-615 Web Configuration adv_routing.php os command injection Vulnerability database entry
- VDB-344854 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #748032 | Dlink DIR-615 v4.10 OS Command Injection Third-party advisory
- Exploit / PoC
- dlink.com