CVE-2019-10999
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).
Published:May 6, 2019
Last Modified:Nov 21, 2024
EPS:May 6, 2019
EPSS Score:0.35804
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Dlink
Product
Dcs-5009l
Dlink
Dcs-5009l
Vendor
Dlink
Product
Dcs-5009l Firmware
Dlink
Dcs-5009l Firmware
Vendor
Dlink
Product
Dcs-5010l
Dlink
Dcs-5010l
Vendor
Dlink
Product
Dcs-5010l Firmware
Dlink
Dcs-5010l Firmware
Vendor
Dlink
Product
Dcs-5020l
Dlink
Dcs-5020l
Vendor
Dlink
Product
Dcs-5020l Firmware
Dlink
Dcs-5020l Firmware
Vendor
Dlink
Product
Dcs-5025l
Dlink
Dcs-5025l
Vendor
Dlink
Product
Dcs-5025l Firmware
Dlink
Dcs-5025l Firmware
Vendor
Dlink
Product
Dcs-5030l
Dlink
Dcs-5030l
Vendor
Dlink
Product
Dcs-5030l Firmware
Dlink
Dcs-5030l Firmware
Vendor
Dlink
Product
Dcs-930l
Dlink
Dcs-930l
Vendor
Dlink
Product
Dcs-930l Firmware
Dlink
Dcs-930l Firmware
Vendor
Dlink
Product
Dcs-931l
Dlink
Dcs-931l
Vendor
Dlink
Product
Dcs-931l Firmware
Dlink
Dcs-931l Firmware
Vendor
Dlink
Product
Dcs-932l
Dlink
Dcs-932l
Vendor
Dlink
Product
Dcs-932l Firmware
Dlink
Dcs-932l Firmware
Vendor
Dlink
Product
Dcs-933l
Dlink
Dcs-933l
Vendor
Dlink
Product
Dcs-933l Firmware
Dlink
Dcs-933l Firmware
Vendor
Dlink
Product
Dcs-934l
Dlink
Dcs-934l
Vendor
Dlink
Product
Dcs-934l Firmware
Dlink
Dcs-934l Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
