Executive brief
A security vulnerability exists in the D-Link DCS-935L HD Wi-Fi camera, a device used for home and small business monitoring. An attacker can exploit this flaw to gain full control over the camera, allowing them to view live video feeds, access private recordings, or disable the device entirely. This could lead to a significant breach of privacy and physical security for users of the affected camera.
Technical details
A format string vulnerability (CWE-134) exists in the '/web/cgi-bin/greece/rhea' CGI binary of the D-Link DCS-935L IP camera. The issue stems from the 'snprintf' function improperly handling the 'sn' and 'hwv' HTTP parameters by passing user-supplied input directly as a format string argument. A remote, authenticated attacker can exploit this by sending specially crafted GET requests to leak stack memory or write arbitrary values to memory using format specifiers like '%n'. Successful exploitation can lead to arbitrary code execution with root privileges. While authentication is typically required, requests originating from localhost (127.0.0.1) may bypass these checks.
Affected products
- D-Link DCS-935L HD Wi-Fi Camera 1.10.01 (Build 20161128)
Timeline
- 2026-05-26: disclosed: Vulnerability discovered by researcher
- 2026-06-13: advisory: NVD/VulDB publication date