Executive brief
Multiple D-Link network cameras contain a security flaw that allows an attacker to take control of the device. These cameras are used for security monitoring, and an exploit could allow an unauthorized person to disrupt video feeds or use the camera as a foothold to attack other parts of the corporate network. Because many of these devices are reaching their end-of-life, users are advised to update their firmware or replace the hardware entirely.
Technical details
A command injection vulnerability exists in the 'cgi-bin/ddns_enc.cgi' endpoint of several D-Link camera models. The flaw is caused by improper neutralization of special elements (CWE-77) within the Dynamic DNS (DDNS) encryption component. An attacker with low-privileged credentials can send specially crafted network requests to execute arbitrary system commands. This vulnerability has been observed in active exploitation. While some models have received hotfixes, many affected devices are considered End-of-Life (EoL), and the vendor recommends discontinuing their use if patches are unavailable.
Affected products
- D-Link DCS-2530L Firmware before 1.06.01 Hotfix
- D-Link DCS-2670L Firmware up to 2.02
- D-Link DCS-4603 Firmware before 1.04.02
- D-Link DCS-4622 Firmware before 2.01.10
- D-Link DCS-4701E Firmware before 2.03.01
- D-Link DCS-4703E Firmware before 1.03.04
- D-Link DCS-4705E Firmware before 1.03.02
- D-Link DCS-4802E Firmware before 2.01.01
Timeline
- 2020-09-11: disclosed: Initial NIST analysis published
- 2025-08-05: kev added: Added to CISA Known Exploited Vulnerabilities catalog