CVE-2025-5572

D-Link · DCS-932L

A critical stack-based buffer overflow in the D-Link DCS-932L setSystemEmail function allows remote exploitation via the EmailSMTPPortNumber argument.

Executive summary

The D-Link DCS-932L camera is affected by a critical stack-based buffer overflow, posing a significant risk of remote code execution.

Vulnerability

This is a critical stack-based buffer overflow in the setSystemEmail function. The vulnerability is remotely exploitable via the EmailSMTPPortNumber argument and requires low-privilege authentication, which is often default on these devices.

Business impact

With a CVSS score of 8.8, this vulnerability presents a high risk to the organization. Because the product is end-of-life, it is particularly susceptible to persistent attacks, potentially allowing unauthorized actors to monitor sensitive environments or gain a foothold in the network.

Remediation

Immediate Action: As this product is end-of-life and will not receive official patches, replace the device with a modern, supported alternative.

Proactive Monitoring: Monitor logs for unauthorized login attempts and inspect traffic for malicious payloads targeting SMTP configuration parameters.

Compensating Controls: Isolate the device from the internet and restrict access to the management interface to prevent external exploitation.

Exploitation status

Public Exploit Available: True

Analyst recommendation

Due to the lack of vendor support and the critical nature of this vulnerability, immediate decommissioning is strongly recommended. Continued use of these devices poses an unacceptable security risk to the enterprise.