CVE-2025-10779

8.8

D-Link · DCS-935L

A stack-based buffer overflow in the D-Link DCS-935L /HNAP1/ endpoint allows remote attackers to trigger memory corruption via a manipulated HNAP_AUTH/SOAPAction argument.

Executive summary

A critical stack-based buffer overflow in the D-Link DCS-935L camera allows remote attackers to potentially execute code or crash the device, posing a severe security risk.

Vulnerability

The vulnerability exists within the sub_402280 function of the /HNAP1/ interface. An authenticated attacker can trigger a stack-based buffer overflow by sending a maliciously crafted HNAP_AUTH/SOAPAction argument to the device.

Business impact

The exploitation of this vulnerability can lead to a complete compromise of the affected camera, allowing for unauthorized access to video streams or the potential execution of arbitrary code with high privileges. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to significant privacy breaches and the integration of these devices into botnets. Organizations utilizing these cameras should prioritize mitigation to avoid reputational damage and potential loss of data integrity.

Remediation

Immediate Action: As the product is no longer supported by the vendor, there is no official security patch available. Users should immediately isolate these devices from the public internet or replace them with supported hardware.

Proactive Monitoring: Security teams should monitor network traffic for abnormal patterns directed at the /HNAP1/ endpoint and review device logs for signs of unauthorized access or repeated service crashes.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) to filter malicious requests containing abnormally long HNAP_AUTH or SOAPAction headers.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the vulnerability researcher.

Analyst recommendation

Because the D-Link DCS-935L has reached its end-of-life and no security updates will be provided, the risk of continued use is extreme. We strongly recommend immediate decommissioning of all affected units from production environments. If immediate removal is not possible, ensure these devices are strictly segmented behind a firewall with no direct exposure to the internet to prevent remote exploitation.

More D-Link CVEs

Sources

Originally found and disclosed by Lexpl0it (VulDB User), per the CVE Program record.