CVE-2026-5815
8.8D-Link · DIR-645
A stack-based buffer overflow in the hedwigcgi_main function of D-Link DIR-645 allows remote attackers to achieve remote code execution.
Executive summary
A critical stack-based buffer overflow vulnerability in D-Link DIR-645 routers enables remote code execution and full device compromise.
Vulnerability
The vulnerability exists within the hedwigcgi_main function of the /cgi-bin/hedwig.cgi file, where improper length checks during the processing of HTTP requests allow a stack-based buffer overflow. This flaw can be triggered by a remote attacker with low privileges by supplying a crafted session identifier.
Business impact
Successful exploitation of this vulnerability allows an attacker to hijack the execution flow of the router, leading to arbitrary remote code execution. This grants the attacker full control over the affected network device, potentially facilitating unauthorized network access, data interception, and persistence within the local environment. Given the CVSS score of 8.8, this vulnerability poses a significant risk to the integrity and confidentiality of the internal network.
Remediation
Immediate Action: Since the vendor has designated this product as end-of-life and no patch is available, the primary remediation is to decommission the device and replace it with a currently supported model.
Proactive Monitoring: Monitor network traffic for unusual POST requests targeting the /cgi-bin/hedwig.cgi endpoint, which may indicate attempts to exploit this buffer overflow.
Compensating Controls: If immediate replacement is not feasible, isolate the device behind a robust firewall and restrict access to the web management interface to trusted administrative IP addresses only.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the researcher's GitHub repository.
Analyst recommendation
The D-Link DIR-645 is an aging device that no longer receives security updates, making it inherently vulnerable to sophisticated attacks. Organizations still utilizing this hardware should prioritize its immediate replacement, as no software patch will be issued to mitigate this critical remote code execution flaw. Continued use of this device constitutes an unacceptable security risk to the organization.
More D-Link CVEs
Sources
Originally found and disclosed by Pers1st (VulDB User), per the CVE Program record.
- VDB-356263 | D-Link DIR-645 hedwig.cgi hedwigcgi_main stack-based overflow Vulnerability database entry
- VDB-356263 | CTI Indicators (IOB, IOC, IOA)
- Submit #788298 | D-Link DIR-645 1.01–1.03 Stack-based Buffer Overflow Third-party advisory
- Related
- Exploit / PoC
- dlink.com