CVE-2016-11021
KEV PoC largeAuthenticated OS Command Injection in D-Link DCS-930L Cameras Allows RCE
CISA: D-Link DCS-930L Devices OS Command Injection Vulnerability
D-Link DCS-930L network cameras running firmware versions before 2.12 contain an OS command injection flaw (CWE-78) in the setSystemCommand handler. An attacker with access to the camera's web interface (the CVSS vector requires high privileges, indicating an authenticated, admin-level request) submits an operating-system command in the SystemCommand parameter, and the device executes it without proper validation. Successful exploitation yields remote code execution on the camera, enabling device takeover, pivoting into the local network, or recruitment into IoT botnets such as BotenaGo, which bundles 33 exploits targeting millions of consumer IoT devices. Any DCS-930L deployment on pre-2.12 firmware is affected, and the product is end-of-life, so CISA's required action is to disconnect it if still in use. The flaw is listed in CISA's KEV catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries a 68.9% EPSS probability of exploitation within 30 days (99th percentile), indicating confirmed in-the-wild exploitation; ransomware use is unknown.
What to do: Update affected DCS-930L cameras to firmware 2.12 or later if obtainable; because the product is end-of-life, CISA's required action is to disconnect or retire any unit still in service. Until remediated, keep the camera's management interface off direct internet exposure and restrict administrative access. Verify the running firmware version and watch for signs of compromise such as unexpected outbound traffic.
| D-Link DCS-930L network camera firmware | All firmware versions before 2.12 (fixed in 2.12) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
- Affected
- D-Link DCS-930L Devices
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dcs-930l firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H