Executive brief
The setSystemCommand function on D-Link DCS-930L devices contains an OS command injection vulnerability. A remote attacker with high privileges can execute arbitrary code via the SystemCommand parameter.
Affected products
- D-Link DCS-930L Firmware before 2.12
- D-Link DCS-930L
Timeline
- 2020-03-08: disclosed: NVD Published Date
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: exploited: Reported as exploited in the wild in CISA KEV catalog