CVE-2015-2049: Critical severity d-link dcs-931l firmware vulnerability
Published Feb 23, 2015
·Updated
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
Affected Software
2 affected components
Dlink Dcs-931l Firmware<=1.04
Dlink Dcs-931l
Event History
Feb 23, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2049?
CVE-2015-2049 is considered to have a critical severity level due to the potential for remote code execution.
2
How do I fix CVE-2015-2049?
To fix CVE-2015-2049, update the D-Link DCS-931L firmware to version 1.05 or later.
3
Who is affected by CVE-2015-2049?
Anyone using the D-Link DCS-931L with firmware version 1.04 or earlier is affected by CVE-2015-2049.
4
What types of attacks can be done via CVE-2015-2049?
CVE-2015-2049 allows attackers to upload malicious executable files, potentially leading to arbitrary code execution.
5
Is CVE-2015-2049 a local or remote vulnerability?
CVE-2015-2049 is a remote vulnerability that requires authenticated users to exploit it.