CVE-2026-2260
- EPSS 0.08%
- Veröffentlicht 10.02.2026 03:02:07
- Zuletzt bearbeitet 12.02.2026 15:33:09
A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argument AdminID results in os command injection. The attack can be executed remotely. The exploit has be...
CVE-2026-2227
- EPSS 0.07%
- Veröffentlicht 09.02.2026 10:02:09
- Zuletzt bearbeitet 23.02.2026 11:16:25
A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploi...
CVE-2019-10999
- EPSS 35.8%
- Veröffentlicht 06.05.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:20:19
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption paramet...
CVE-2017-7852
- EPSS 0.89%
- Veröffentlicht 24.04.2017 10:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, ...
- EPSS 82.87%
- Veröffentlicht 23.02.2015 17:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
CVE-2015-2048
- EPSS 0.07%
- Veröffentlicht 23.02.2015 17:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.