D-Link DCS-932L
cpe:2.3:h:d-link:dcs-932l:*:*:*:*:*:*:*, +4 more
- 2.18.01
A critical command injection vulnerability has been identified in the D-Link DCS-932L camera, specifically in version 2.18.01. The issue arises in the 'setSystemAdmin' function, where the 'AdminID' parameter can be manipulated to execute arbitrary operating system commands. This vulnerability can be exploited remotely and affects products that are no longer supported by the manufacturer.
Exploitation of this vulnerability allows for remote command execution on the affected device.
To reproduce this vulnerability, send a POST request to the '/setSystemAdmin' endpoint with a crafted 'AdminID' parameter. The payload should include the desired OS command, such as 'telnetd', which will be executed by the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.