ZeroHour

CVE-2016-11021

KEV PoC large

Authenticated OS Command Injection in D-Link DCS-930L Cameras Allows RCE

CISA: D-Link DCS-930L Devices OS Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
69%p99
Published
()
KEV added
AI analysis

D-Link DCS-930L network cameras running firmware versions before 2.12 contain an OS command injection flaw (CWE-78) in the setSystemCommand handler. An attacker with access to the camera's web interface (the CVSS vector requires high privileges, indicating an authenticated, admin-level request) submits an operating-system command in the SystemCommand parameter, and the device executes it without proper validation. Successful exploitation yields remote code execution on the camera, enabling device takeover, pivoting into the local network, or recruitment into IoT botnets such as BotenaGo, which bundles 33 exploits targeting millions of consumer IoT devices. Any DCS-930L deployment on pre-2.12 firmware is affected, and the product is end-of-life, so CISA's required action is to disconnect it if still in use. The flaw is listed in CISA's KEV catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries a 68.9% EPSS probability of exploitation within 30 days (99th percentile), indicating confirmed in-the-wild exploitation; ransomware use is unknown.

What to do: Update affected DCS-930L cameras to firmware 2.12 or later if obtainable; because the product is end-of-life, CISA's required action is to disconnect or retire any unit still in service. Until remediated, keep the camera's management interface off direct internet exposure and restrict administrative access. Verify the running firmware version and watch for signs of compromise such as unexpected outbound traffic.

Affected
D-Link DCS-930L network camera firmwareAll firmware versions before 2.12 (fixed in 2.12)
Estimated exposure
largetens of thousands of internet-exposed cameras (millions of units sold historically; many EOL devices still deployed) — Estimated from the DCS-930L's history as one of D-Link's best-selling consumer cloud cameras (millions of units shipped), the long service life typical of EOL consumer IoT devices, and public internet-scan visibility of this camera model,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

CISA Known Exploited Vulnerability
Affected
D-Link DCS-930L Devices
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dcs-930l firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news