peter bassill · operator
$ cve CVE-2017-11563 JSON

CVE-2017-11563

9.8
CRITICAL · CVSS 3.0 · EPSS 5.2% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP "Discover" service, which provides multiple functions such as changing the passwords and getting basic information, was installed on the device. A remote attacker can send a crafted UDP request to finderd to perform stack overflow and execute arbitrary code with root privilege on the device.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.2% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2018-08-24
Last modified2026-06-17

Affected (2)

VendorProduct
dlinkeyeon baby monitor
dlinkeyeon baby monitor firmware

References

→ the Explorer  ·  watch your stack  ·  NVD