Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

D-Link DIR-645 HNAP SOAPAction Command Injection

IdentifiersCVE-2015-2051CWE-78

CVE-2015-2051 is a remote command injection vulnerability in the HNAP interface of the D-Link DIR-645 Wired/Wireless Router Rev. Ax. Affected devices running firmware 1.04b12 and earlier improperly handle the HNAP GetDeviceSettings action, allowing a remote attacker to inject arbitrary commands via the SOAPAction header or associated HNAP request processing. The flaw is repeatedly described in the provided material as an HNAP SOAPAction command execution/injection issue affecting the DIR-645 management interface.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows a remote attacker to execute arbitrary operating system commands on the vulnerable router. This can result in full compromise of the device, including unauthorized control of router functions, malware installation, botnet enrollment, persistence, traffic interception or manipulation, and use of the device as a pivot for further network activity or DDoS operations.

Mitigation

If you can’t patch tonight, do this now.

Disable or restrict access to the HNAP interface wherever possible, especially from the WAN/Internet. Limit administrative access to trusted internal hosts or a dedicated management network, enforce firewall rules to block external access to router management services, and monitor for exploitation attempts referencing HNAP or GetDeviceSettings. Where immediate patching is not possible, isolate the device, disable remote administration, and apply IPS protections such as signatures for D-Link HNAP SOAPAction command execution attempts.

Remediation

Patch, then assume compromise.

Upgrade the D-Link DIR-645 Rev. Ax to a fixed firmware release later than 1.04b12, if an official vendor patch is available. If the product is end-of-life or no patched firmware is available, replace the device with supported hardware. Restrict exposure of the router management and HNAP interfaces from untrusted networks and verify that internet-facing administrative access is disabled.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
D-LinkDir-645hardware
D-LinkDir-645 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence2

Every observed campaign linking this CVE to a named adversary.

Associated malware6

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.