peter bassill · operator
$ cve CVE-2017-17020 JSON

CVE-2017-17020 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 14.8% (pctl 97)

Patch early

A public exploit exists.

Description

On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server) allows remote authenticated attackers to execute code through sanitized /setSystemAdmin user input in the AdminID field being passed directly to a call to system.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS14.84% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2018-05-01
Last modified2026-06-17

Affected (6)

VendorProduct
dlinkdcs-5009
dlinkdcs-5009 firmware
dlinkdcs-5010
dlinkdcs-5010 firmware
dlinkdcs-5020l
dlinkdcs-5020l firmware

Public exploits

SourceTitleDate
exploit-dbDLINK DCS-5020L - Remote Code Execution (PoC)2018-03-27

References

→ the Explorer  ·  watch your stack  ·  NVD