D-Link DCS-700L Path Traversal Vulnerability in Music File Upload Service
Vulnerability
A path traversal vulnerability has been identified in the D-Link DCS-700L camera running firmware version 1.03.09. The issue arises in the Music File Upload Service, specifically within the 'uploadmusic' function of the '/setUploadMusic' file. This vulnerability allows for the manipulation of the 'UploadMusic' argument, enabling attackers to traverse directories and access files outside the intended directory. The vulnerability can only be exploited from within the local network, and it affects products that are no longer supported by the manufacturer.
Impact
Exploitation of this vulnerability allows for path traversal, enabling access to files outside the intended directory. This could lead to the disclosure of sensitive system files, such as configuration files or user credentials.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
