CVE-2017-17020
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server) allows remote authenticated attackers to execute code through sanitized /setSystemAdmin user input in the AdminID field being passed directly to a call to system.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 14.84% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- dlink/dcs-5009 firmware · dlink/dcs-5010 firmware · dlink/dcs-5020l firmware
- Source
- cve@mitre.org
References
- http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10084Vendor Advisory
- https://www.fidusinfosec.com/dlink-dcs-5030l-remote-code-execution-cve-2017-17020/Exploit, Third Party Advisory
- http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10084Vendor Advisory
- https://www.fidusinfosec.com/dlink-dcs-5030l-remote-code-execution-cve-2017-17020/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.