CVE-2016-11021highunder attackCWE-78

CVE-2016-11021

Published · Updated

98Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.2epss 69%
from disclosure to weapon0 days
Published on NVDMar 9
metasploitDec 20
CISA KEV+746d
exploitation probability
69%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-04-15

The impacted product is end-of-life and should be disconnected if still in use.

In short

A D-Link DCS-930L camera before version 2.12 allows attackers to run arbitrary commands on the device by sending specially crafted requests. This means someone could take control of your camera and do whatever they want with it.

Technical detail

OS command injection vulnerability in the setSystemCommand function on D-Link DCS-930L firmware versions prior to 2.12. The SystemCommand parameter is not properly sanitized, allowing unauthenticated or low-privilege remote attackers to execute arbitrary OS commands with device privileges. Exploitation requires network access to the affected endpoint.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.