Evidence dossier

CVE-2015-1187

CVE-2015-1187

82.798.2Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

State
PUBLISHED
Published
Sep 21, 2017
Updated
Oct 21, 2025
Evidence coverage
72%
CISA KEVCatalog member

The impacted product is end-of-life and should be disconnected if still in use.

FIRST EPSS82.86%

2026-07-18 · v2026.06.15 · percentile 99.6%

Source stateConflict visible

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

mitreoriginal assertion
container

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

CISA KEVoriginal assertion
observed_exploitation

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.828630000000; percentile 0.996360000000

Applicability

Cited product scope

Trace impact →
36Underlying assertions
30Canonical products
18Target assertions
18Constraint assertions

Grouped from 36 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

31 scope groups

mitre · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · HARDWAREdlinkdir-626lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-acd26a8d1f3b5d61b40ba8ae8c7ccbed87834418e0b57c7b93b123f0da19c786linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:dlink:dir-626l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb204438-1cbb-4a4d-9186-06acfd4822de
NVD CPE · OPERATING SYSTEMdlinkdir-626l_firmwareVulnerable target · 1 assertions
Version 1.04Canonical identity product-81bd9b42213edc4e622b65783dfaaccec9a8fd49a4460231e4c97d4b093b9572linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:dlink:dir-626l_firmware:1.04:b04:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c61317c-44bd-4683-a5e9-8c0ca765ec4e
NVD CPE · HARDWAREdlinkdir-636lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-6c0ef0a76506bcb22189812b8f81f3536f6372ed0388be4cf116d1c1afff49fclinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:dlink:dir-636l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9adefad1-c800-4823-b546-514389c31391
NVD CPE · OPERATING SYSTEMdlinkdir-636l_firmwareVulnerable target · 1 assertions
Version 1.04Canonical identity product-3cc50a2c1c0245ae1b861351806003f599b78f373c7e4f6b0887d9f85350ccc3linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:dlink:dir-636l_firmware:1.04:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7b2daf60-5e3c-443c-9baa-2301d6e6ccfe
NVD CPE · HARDWAREdlinkdir-651Environmental constraint · 1 assertions
Version not applicableCanonical identity product-3cdb7654a52032f0c634787d56a4e15159e2d6b8f57b505eacf3777a079a4e15linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:dlink:dir-651:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    14e7e497-fdc7-4d4f-9313-10c21d9b58e2
NVD CPE · OPERATING SYSTEMdlinkdir-651_firmwareVulnerable target · 1 assertions
Version 1.10naCanonical identity product-4bc1c483238fa98be999adc2b1f61ee650fa0219bd9c45ac5c4ab8d05fcd4ee7linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:dlink:dir-651_firmware:1.10na:b02:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5ba8648e-8d38-4355-9ccc-a1c441fcbc02
NVD CPE · HARDWAREdlinkdir-808lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-25c5f063340bad3bf5da8face90978921eccfe529becff83cf553e45937dda7dlinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:dlink:dir-808l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7d074d3-db9d-4232-947a-6c312e438947
NVD CPE · OPERATING SYSTEMdlinkdir-808l_firmwareVulnerable target · 1 assertions
Version 1.03Canonical identity product-cc8a691f837c04e16767544466b3e2507db8d6648b4f0b54534b362b5eed9501linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:dlink:dir-808l_firmware:1.03:b05:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9437b000-d0bf-4ece-ab9a-7e0e5a4c8cbd
NVD CPE · HARDWAREdlinkdir-810lEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-a6cd94951d84f6a2965094b8879bfdf9d7fddf5b5c06842ed73f165c8098041alinked exact
constrained
Inspect 2 returned assertions
  1. cpe:2.3:h:dlink:dir-810l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8b79563c-609a-4f9f-8f2f-fff3d10e6684
  2. cpe:2.3:h:dlink:dir-810l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8b79563c-609a-4f9f-8f2f-fff3d10e6684
NVD CPE · OPERATING SYSTEMdlinkdir-810l_firmwareVulnerable target · 2 assertions
Version 1.01; Version 2.02Canonical identity product-95c81649557094c7570667986dbd69caf3fc7cea282c9052ca62e1338f7ee58elinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:dlink:dir-810l_firmware:2.02:b01:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00cf9b1b-0281-44f8-8182-cb4ae6667c93
  2. cpe:2.3:o:dlink:dir-810l_firmware:1.01:b04:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c345217-7afd-4521-92b0-57a43963dc3a
NVD CPE · HARDWAREdlinkdir-820lEnvironmental constraint · 3 assertions
Version not applicableCanonical identity product-77dd15fc713af02af2caf6ce98aba53e95b8082ca5eaad9d63e796c608e8e670linked exact
constrained
Inspect 3 returned assertions
  1. cpe:2.3:h:dlink:dir-820l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88ce60cd-dcda-43e0-80a9-257557edbc29
  2. cpe:2.3:h:dlink:dir-820l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88ce60cd-dcda-43e0-80a9-257557edbc29
  3. cpe:2.3:h:dlink:dir-820l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88ce60cd-dcda-43e0-80a9-257557edbc29
NVD CPE · OPERATING SYSTEMdlinkdir-820l_firmwareVulnerable target · 3 assertions
Version 1.02; Version 1.05; Version 2.01Canonical identity product-e4c4f4a926131189fb124e8748d03d68ecc715f25b1e7c9193d23b126544af5dlinked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:o:dlink:dir-820l_firmware:2.01:b02:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    85afe680-0ecf-43b7-b4b6-1f9d4fb96fe9
  2. cpe:2.3:o:dlink:dir-820l_firmware:1.05:b03:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ead0e2a6-b7f2-4614-afd9-7b9414a3773e
  3. cpe:2.3:o:dlink:dir-820l_firmware:1.02:b10:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    73616482-c6f8-45b2-afa9-cc58600d1259
NVD CPE · HARDWAREdlinkdir-826lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-fa46764e2e1b5a0dd0f4549bfe154466b29fce06f9573fd7fc0d26b4d386f751linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:dlink:dir-826l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    36554d63-d4a3-499a-bd79-8c8729cb003e
NVD CPE · OPERATING SYSTEMdlinkdir-826l_firmwareVulnerable target · 1 assertions
Version 1.00Canonical identity product-f1a1f4dc6ec8473f8f49de53032d3250ff9a1076c73dc8c0b09b9f55a9272655linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:dlink:dir-826l_firmware:1.00:b23:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0a250a29-4b67-415c-9209-8da3ca7787b4
NVD CPE · HARDWAREdlinkdir-830lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0ac3d4860e2445dc2a31bb25a58ce16d91a9ec97d6d71f05cc1d9427b2444fbdlinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:dlink:dir-830l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    889685bb-efd4-46ca-bbf1-f215dad02c92
NVD CPE · OPERATING SYSTEMdlinkdir-830l_firmwareVulnerable target · 1 assertions
Version 1.00Canonical identity product-0d9a94bffe69c1b7026949998d4721987e7dc0033746a49a3c7f8d23c8ef51e1linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:dlink:dir-830l_firmware:1.00:b07:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    df1985bb-b6d5-49af-8b58-1e0e15c0a606
NVD CPE · HARDWAREdlinkdir-836lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-6c44c29cbcd07ecaafb1e6457aedd751e2ea117ba37a765b90230ef35063e990linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:dlink:dir-836l:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee2ed91b-738d-448b-b7e0-d869539571f1
NVD CPE · OPERATING SYSTEMdlinkdir-836l_firmwareVulnerable target · 1 assertions
Version 1.01Canonical identity product-5e55d61ac8d56358cb92e3a98569706b3228d1af2f0e08290bb083ceadf71e6alinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:dlink:dir-836l_firmware:1.01:b03:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b26e3cf6-4b1d-46d5-b4a0-cb0bc6cc3a8e
NVD CPE · HARDWAREtrendnettew-651brEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0d42e49ea02e4875c71c163ae59943de9f5a3508a4948818805742867907c26alinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:trendnet:tew-651br:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    13 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e4956be-1836-44ce-a87b-8f6956f969c5
NVD CPE · OPERATING SYSTEMtrendnettew-651br_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-8ac0a87c02fd3359b958b6da7c9c13a8462c826e209d0080928cc59ec6592cfelinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:trendnet:tew-651br_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    71bf3a98-ec0c-4ae4-9319-05e1273ca840
NVD CPE · HARDWAREtrendnettew-652brEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b380b7b234eb70412173317c4470d9161148836ebaf1a27d0f1beab5667390d1linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:trendnet:tew-652br:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    14 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c00dd34c-71b8-471e-b6de-d7347b1a2a3a
NVD CPE · OPERATING SYSTEMtrendnettew-652br_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-6abda2b06edece24c85c4ea309fbb31d5bda53084bb09da968a2632b997491e3linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:trendnet:tew-652br_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0fa8f5f2-2d77-462e-8e10-bcb455e897ab
NVD CPE · HARDWAREtrendnettew-711brEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-10d8ff9f915e6ab5ce8e772eb79749c63c2a13767bccfe3de90ad7f7bf78dac2linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:trendnet:tew-711br:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    15 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52dc8c5f-a9b1-4842-a258-7ec51b070b36
NVD CPE · OPERATING SYSTEMtrendnettew-711br_firmwareVulnerable target · 1 assertions
Version 1.00Canonical identity product-7220fd1b4d95a6b121381f64df8d341fa534950fd27baf3b950dd31b4604e894linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:trendnet:tew-711br_firmware:1.00:b31:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    effb5cc1-c372-4eaf-8eb1-89d722bb8224

Assessments

CVSS by origin

9.8
nvd@nist.govCVSS 3.1 · role PrimaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.