Junglewise Threat Intelligence

CVE-2016-11021: D-Link DCS-930L Devices OS Command Injection Vulnerability

CVE-2016-11021 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2022-03-25

Vendors: D-Link.

Executive brief

The setSystemCommand function on D-Link DCS-930L devices contains an OS command injection vulnerability. A remote attacker with high privileges can execute arbitrary code via the SystemCommand parameter.

Affected products

  • D-Link DCS-930L Firmware before 2.12
  • D-Link DCS-930L

Timeline

  • 2020-03-08: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: exploited: Reported as exploited in the wild in CISA KEV catalog