cbcvebase.
CVE-2017-17020
published 2018-05-01

CVE-2017-17020: On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before…

PriorityP270high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
15.06%
96.3th percentile
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server) allows remote authenticated attackers to execute code through sanitized /setSystemAdmin user input in the AdminID field being passed directly to a call to system.

Affected

3 ranges
VendorProductVersion rangeFixed in
dlinkdcs-5009_firmware<= 1.08.11
dlinkdcs-5010_firmware<= 1.14.09
dlinkdcs-5020l_firmware<= 1.14.09

Detection & IOCsextracted from sources · hover to see the quote

path/setSystemAdmin
processalphapd
  • Monitor HTTP requests to the /setSystemAdmin endpoint on D-Link DCS camera web interfaces for AdminID field values containing backtick characters (`) or shell metacharacters indicative of command injection attempts.
  • ·Exploitation requires prior authentication; the attacker must have valid credentials to reach the /setSystemAdmin endpoint. Unauthenticated access alone is insufficient to trigger the injection.
  • ·Affected firmware versions are: DCS-5009 ≤ 1.08.11, DCS-5010 ≤ 1.14.09, and DCS-5020L < 1.15.01. Detection rules should be scoped to these device/firmware combinations.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.