Junglewise Threat Intelligence

CVE-2026-13545: D-Link DCS-935L OS command injection in setconf.cgi

CVE-2026-13545 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: D-Link DCS-935L. Vendors: D-Link.

Executive brief

A security vulnerability exists in the D-Link DCS-935L, a Wi-Fi camera used for home and business monitoring. An attacker can remotely inject malicious commands into the device's configuration interface. If exploited, this allows an attacker to take full control of the camera, potentially leading to unauthorized surveillance, data theft, or the device being used as a foothold to attack other parts of the network.

Technical details

An OS command injection vulnerability exists in the D-Link DCS-935L camera running firmware version 1.10.01. The flaw is located within the 'sub_400E40' function of the 'setconf.cgi' file, which serves as a POST parameter handler. Specifically, the 'UID' argument is not properly neutralized before being used in a system command. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to execute arbitrary operating system commands. Public exploit code has been disclosed for this vulnerability.

Affected products

  • D-Link DCS-935L 1.10.01

Timeline

  • 2026-06-29: disclosed: Exploit disclosed to the public
  • 2026-06-29: advisory

References

Related threats