CVE-2016-11021: D-Link DCS-930L Devices OS Command Injection Vulnerability
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
Other sources
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DCS-930Lto a version that resolves this vulnerability.Fixed in 2.12 - Compensating control
Disconnect D-Link DCS-930L devices if still in use (device is end-of-life); isolate them from networks or power them off to prevent remote exploitation.
Event History
Frequently Asked Questions
What is CVE-2016-11021?
CVE-2016-11021 is a vulnerability that allows a remote attacker to execute code via an OS command injection in D-Link DCS-930L devices before version 2.12.
How severe is CVE-2016-11021?
CVE-2016-11021 has a severity score of 7.2 (critical).
Which software is affected by CVE-2016-11021?
D-Link DCS-930L devices before version 2.12 are affected by CVE-2016-11021.
How can an attacker exploit CVE-2016-11021?
An attacker can exploit CVE-2016-11021 by sending a malicious OS command in the SystemCommand parameter.
Is there a fix for CVE-2016-11021?
Yes, the vulnerability can be fixed by updating D-Link DCS-930L devices to version 2.12 or later.