---
id: CVE-2025-15194
title: A vulnerability was found in D-Link DIR-600 up to 2.15WWb02
summary: >-
  A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this
  vulnerability is an unknown functionality of the file hedwig.cgi of the
  component HTTP Header Handler. The manipulation of the argument Cookie results
  in stack…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-121
vendor: dlink
product: dir-600_firmware
affected:
  - dir-600_firmware = 2.15ww
published: '2025-12-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15194'
references:
  - url: >-
      https://github.com/LonTan0/CVE/blob/main/Stack-Based%20Buffer%20Overflow%20Vulnerability%20in%20hedwig.cgi%20of%20D-Link%20DIR-600.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/LonTan0/CVE/blob/main/Stack-Based%20Buffer%20Overflow%20Vulnerability%20in%20hedwig.cgi%20of%20D-Link%20DIR-600.md#poc
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338581'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338581'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.724404'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0118
epssPercentile: 0.66647
ingestedAt: '2026-10-05T19:30:59.955Z'
---

## Overview

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

## Affected

- `dir-600_firmware = 2.15ww`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
