PatchSiren cyber security CVE debrief
CVE-2017-5633 D Link CVE debrief
CVE-2017-5633 is a HIGH-severity CSRF issue in the D-Link DI-524 Wireless Router firmware 9.01. According to NVD, crafted requests to CGI programs can let an attacker trigger admin-password changes, device reboots, and possibly other unspecified effects.
- Vendor
- D Link
- Product
- CVE-2017-5633
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-06
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-06
- Advisory updated
- 2026-05-13
Who should care
Organizations or individuals still operating D-Link DI-524 devices on firmware 9.01, especially if the router management interface is reachable from untrusted networks or used in small-office/home-office environments.
Technical summary
NVD classifies the issue as CWE-352 (Cross-Site Request Forgery) with CVSS 3.0 vector AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. The vulnerability is described as multiple CSRF flaws affecting CGI programs on the router, enabling actions such as changing the administrator password or rebooting the device when a victim interacts with crafted requests.
Defensive priority
High for exposed or actively managed devices. Even though user interaction is required, the potential impact includes loss of administrative control and service disruption on a network edge device.
Recommended defensive actions
- Confirm whether any D-Link DI-524 units are still in service and running firmware 9.01.
- Restrict router administration to trusted networks only; avoid exposing the management interface to the public internet.
- Apply any vendor-provided firmware fix if available for your device; if no supported fix exists, plan replacement of the legacy router.
- Use separate, hardened administration paths and limit which users can access router management.
- Monitor for unexpected admin-password changes, configuration drift, and unsolicited reboots on affected devices.
Evidence notes
The description and severity come from the supplied NVD record for CVE-2017-5633, which lists the affected CPE as d-link DI-524 firmware 9.01 and the weakness as CWE-352. The supplied record also provides the CVSS 3.0 vector AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. Published date: 2017-03-06T06:59:00.257Z; modified date: 2026-05-13T00:24:29.033Z. No KEV listing is present in the supplied data.
Official resources
-
CVE-2017-5633 CVE record
CVE.org
-
CVE-2017-5633 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Product, Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
Publicly disclosed on 2017-03-06. The supplied NVD record was modified on 2026-05-13. No CISA KEV entry is included in the supplied data.