CVE-2016-11021
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
The impacted product is end-of-life and should be disconnected if still in use.
A D-Link DCS-930L camera before version 2.12 allows attackers to run arbitrary commands on the device by sending specially crafted requests. This means someone could take control of your camera and do whatever they want with it.
OS command injection vulnerability in the setSystemCommand function on D-Link DCS-930L firmware versions prior to 2.12. The SystemCommand parameter is not properly sanitized, allowing unauthenticated or low-privilege remote attackers to execute arbitrary OS commands with device privileges. Exploitation requires network access to the affected endpoint.
The full analysis of this CVE is available in Portuguese →