PatchSiren cyber security CVE debrief
CVE-2015-1187 D-Link and TRENDnet CVE debrief
CVE-2015-1187 is a remote code execution vulnerability affecting multiple D-Link and TRENDnet devices. It is listed in CISA’s Known Exploited Vulnerabilities catalog, and CISA notes that the impacted product is end-of-life and should be disconnected if still in use.
- Vendor
- D-Link and TRENDnet
- Product
- Multiple Devices
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
Organizations that still operate D-Link or TRENDnet devices covered by this CVE should treat it as urgent, especially if the devices are internet-facing, remotely managed, or otherwise difficult to replace quickly.
Technical summary
The public record identifies this issue as a remote code execution vulnerability in multiple D-Link and TRENDnet devices. The CISA KEV entry classifies it as known exploited and adds operational guidance that the affected product is end-of-life, indicating replacement or disconnection is the safest defensive posture.
Defensive priority
High. The vulnerability is in CISA’s KEV catalog and the affected product is described as end-of-life, so continued use should be minimized and removed from service where possible.
Recommended defensive actions
- Inventory all D-Link and TRENDnet devices to determine whether any are affected by this CVE.
- Disconnect or remove affected end-of-life devices if they remain in use.
- Replace impacted hardware with currently supported alternatives.
- If immediate removal is not possible, reduce exposure by isolating the device from untrusted networks and limiting access to only what is operationally necessary.
- Verify asset ownership and operational dependency so that decommissioning can be scheduled quickly and safely.
Evidence notes
This debrief is based on the CVE record and CISA’s Known Exploited Vulnerabilities catalog entry for CVE-2015-1187. CISA’s note states: 'The impacted product is end-of-life and should be disconnected if still in use.' No affected model list or CVSS score was provided in the supplied corpus.
Official resources
-
CVE-2015-1187 CVE record
CVE.org
-
CVE-2015-1187 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - The impacted product is end-of-life and should be disconnected if still in use.
-
Source item URL
cisa_kev
CVE published and modified on 2022-03-25 in the supplied record; CISA KEV added date is 2022-03-25 and due date is 2022-04-15.