VulnerabilityAnalyzed
CVE-2026-1419
A weakness has been identified in D-Link DCS700l 1.03.09.
LOW 2.0EPSS 15.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 15.39% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-77
- Affected
- dlink/dcs-700l firmware
- Source
- cna@vuldb.com
References
- https://tzh00203.notion.site/D-Link-DCS700l-v1-03-09-Command-Injection-Vulnerability-in-LightSensorControl-Parameter-2e6b5c52018a80ada0f6d7e72efd7a45?source=copy_linkExploit, Third Party Advisory
- https://vuldb.com/?ctiid.342815Permissions Required, VDB Entry
- https://vuldb.com/?id.342815Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.736554Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.