VendorsD-Linkdcs-932lall versions
Vulnerabilities

D-Link DCS-932L

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2025-5573
D-Link DCS-932L setSystemWizard setSystemControl os command injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.138
CVE-2025-4841
D-Link DCS-932L gpio sub_404780 stack-based overflow
Published 2025-05-17 · Analyzed
9.8EPSS 0.013
CVE-2025-4842
D-Link DCS-932L ucp isUCPCameraNameChanged stack-based overflow
Published 2025-05-17 · Analyzed
9.8EPSS 0.013
CVE-2025-4843
D-Link DCS-932L udev SubUPnPCSInit stack-based overflow
Published 2025-05-17 · Analyzed
9.8EPSS 0.013
CVE-2025-5572
D-Link DCS-932L setSystemEmail stack-based overflow
Published 2025-06-04 · Analyzed
9.0EPSS 0.058
CVE-2025-5571
D-Link DCS-932L setSystemAdmin os command injection
Published 2025-06-04 · Analyzed
8.8EPSS 0.136
CVE-2017-7852
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.
Published 2017-04-24 · Modified
8.81 PoCEPSS 0.043
CVE-2019-10999
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).
Published 2019-05-06 · Modified
8.8EPSS 0.036
CVE-2021-41504
An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published 2021-09-24 · Modified
8.0EPSS 0.005
CVE-2021-41503
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published 2021-09-24 · Modified
8.0EPSS 0.004
CVE-2018-18441
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many affected firmware versions starting from 1.00 and above. The configuration file can be accessed remotely through: <Camera-IP>/common/info.cgi, with no authentication. The configuration file include the following fields: model, product, brand, version, build, hw_version, nipca version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker, and sensor settings.
Published 2018-12-20 · Modified
7.5EPSS 0.019
CVE-2026-36983
D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.
Published 2026-05-11 · Analyzed
7.3EPSS 0.023
CVE-2024-37606
A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2024-12-17 · Analyzed
6.5EPSS 0.005
CVE-2012-4046
The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the _paramR["P"] value.
Published 2012-12-24 · Modified
3.3EPSS 0.008