CVE-2026-2260

7.2

D-Link · DCS-931L

A remote OS command injection vulnerability exists in the D-Link DCS-931L camera via the /goform/setSysAdmin endpoint, allowing attackers to execute arbitrary commands by manipulating the AdminID argument.

Executive summary

A critical OS command injection vulnerability in D-Link DCS-931L surveillance cameras allows remote, authenticated attackers to execute arbitrary system commands, potentially leading to full device compromise.

Vulnerability

The flaw resides in the /goform/setSysAdmin file, where improper handling of the AdminID parameter permits OS command injection. While the CVSS vector indicates that high privileges are required, the vulnerability is reachable remotely and allows for complete system impact.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain unauthorized control over the affected camera, leading to potential data exfiltration or the conversion of the device into a botnet node. Given the CVSS score of 7.2, this represents a high-severity risk to organizational security, particularly as the affected hardware is no longer supported by the vendor, meaning no official security patch is expected.

Remediation

Immediate Action: As the affected product is end-of-life and no patch is available, administrators should immediately isolate these devices from the internet or remove them from the production network.

Proactive Monitoring: Monitor network traffic for suspicious outbound connections from the camera devices, specifically looking for unexpected shell activity or unauthorized HTTP POST requests to the /goform/setSysAdmin endpoint.

Compensating Controls: Deploy a Web Application Firewall (WAF) or network-level access control list (ACL) to restrict access to the camera interface to known, trusted management IP addresses only.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided by the vulnerability researcher.

Analyst recommendation

Given that D-Link has ceased support for this model, the risk of unpatched vulnerabilities is permanent. Organizations still utilizing the DCS-931L should prioritize the immediate decommissioning of these units and replace them with currently supported, secure alternatives to ensure long-term network integrity.

More D-Link CVEs

Sources

Originally found and disclosed by cha0yang (VulDB User), per the CVE Program record.