CVE-2018-18441: Infoleak
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many affected firmware versions starting from 1.00 and above. The configuration file can be accessed remotely through: <Camera-IP>/common/info.cgi, with no authentication. The configuration file include the following fields: model, product, brand, version, build, hwversion, nipca version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker, and sensor settings.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18441?
CVE-2018-18441 is a vulnerability in the D-Link DCS series Wi-Fi cameras that exposes sensitive information regarding the device configuration.
Which devices are affected by CVE-2018-18441?
The affected devices include many of the DCS series cameras, such as DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and more.
What is the severity of CVE-2018-18441?
The severity of CVE-2018-18441 is high, with a CVSS base score of 7.5.
How does CVE-2018-18441 affect the affected devices?
CVE-2018-18441 exposes sensitive information regarding the device configuration, which can potentially lead to unauthorized access and compromise of the cameras.
How can I fix CVE-2018-18441?
To fix CVE-2018-18441, it is recommended to update the firmware of the affected devices to the latest version provided by D-Link.