The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1187
Reference (s):
- BID:72848
- URL: http://www.securityfocus.com/bid/72848
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10052
- FULLDISC:20150302 CVE-2015-1187: D-Link DIR-636L Remote Command Injection – Incorrect Authentication
- URL: http://seclists.org/fulldisclosure/2015/Mar/15

