CVE-2017-17020
published 2018-05-01CVE-2017-17020: On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before…
PriorityP270high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
15.06%
96.3th percentile
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server) allows remote authenticated attackers to execute code through sanitized /setSystemAdmin user input in the AdminID field being passed directly to a call to system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dcs-5009_firmware | <= 1.08.11 | — |
| dlink | dcs-5010_firmware | <= 1.14.09 | — |
| dlink | dcs-5020l_firmware | <= 1.14.09 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests to the /setSystemAdmin endpoint on D-Link DCS camera web interfaces for AdminID field values containing backtick characters (`) or shell metacharacters indicative of command injection attempts. ↗
- ·Exploitation requires prior authentication; the attacker must have valid credentials to reach the /setSystemAdmin endpoint. Unauthenticated access alone is insufficient to trigger the injection. ↗
- ·Affected firmware versions are: DCS-5009 ≤ 1.08.11, DCS-5010 ≤ 1.14.09, and DCS-5020L < 1.15.01. Detection rules should be scoped to these device/firmware combinations. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10084https://www.fidusinfosec.com/dlink-dcs-5030l-remote-code-execution-cve-2017-17020/http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10084https://www.fidusinfosec.com/dlink-dcs-5030l-remote-code-execution-cve-2017-17020/
2018-05-01
Published