D-Link DCS-932L
cpe:2.3:h:d-link:dcs-932l:*:*:*:*:*:*:*, +4 more
- 2.18.01
A critical stack-based buffer overflow vulnerability has been identified in the D-Link DCS-932L camera, specifically in version 2.18.01. The issue arises in the 'isUCPCameraNameChanged' function within the '/sbin/ucp' file, where improper handling of the 'CameraName' argument creates the potential for remote exploitation. This vulnerability affects devices that are no longer supported by the manufacturer.
Exploitation of this vulnerability allows for a stack-based buffer overflow, which could lead to arbitrary code execution or causing the device to crash.
The vulnerability can be reproduced by sending a crafted request to the '/sbin/ucp' endpoint, specifically targeting the 'CameraName' argument. This request should be made over the network, as the vulnerability can be exploited remotely.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.