Executive brief
A security vulnerability exists in the D-Link DCS-5615 network camera. The issue involves a configuration file within the device's web server that does not properly enforce access restrictions. An attacker could exploit this remotely to bypass intended security limitations, potentially altering device settings or behavior.
Technical details
A vulnerability classified as Incorrect Privilege Assignment (CWE-266) and Least Privilege Violation (CWE-272) exists in the D-Link DCS-5615 firmware version 1.01.00. The flaw is located within the Boa Webserver component, specifically involving the configuration file /etc/conf.d/boa/boa.conf. An unauthenticated remote attacker can manipulate this functionality to bypass privilege restrictions. While the specific impact is limited to integrity (I:L), the exploit has been disclosed publicly. No official patch is currently detailed in the advisory.
Affected products
- D-Link DCS-5615 1.01.00
Timeline
- 2026-06-08: disclosed: Public disclosure via VulDB and NVD