Vulnerability Description
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dcs-930L Firmware | <= 2.16.01 |
| Dlink | Dcs-930L | - |
| Dlink | Dcs-931L Firmware | <= 1.14.11 |
| Dlink | Dcs-931L | - |
| Dlink | Dcs-932L Firmware | <= 2.17.01 |
| Dlink | Dcs-932L | - |
| Dlink | Dcs-933L Firmware | <= 1.14.11 |
| Dlink | Dcs-933L | - |
| Dlink | Dcs-934L Firmware | <= 1.05.04 |
| Dlink | Dcs-934L | - |
| Dlink | Dcs-5009L Firmware | <= 1.08.11 |
| Dlink | Dcs-5009L | - |
| Dlink | Dcs-5010L Firmware | <= 1.14.09 |
| Dlink | Dcs-5010L | - |
| Dlink | Dcs-5020L Firmware | <= 1.15.12 |
| Dlink | Dcs-5020L | - |
| Dlink | Dcs-5025L Firmware | <= 1.03.07 |
| Dlink | Dcs-5025L | - |
| Dlink | Dcs-5030L Firmware | <= 1.04.10 |
| Dlink | Dcs-5030L | - |
Related Weaknesses (CWE)
References
- https://github.com/fuzzywalls/CVE-2019-10999ExploitThird Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1
- https://github.com/fuzzywalls/CVE-2019-10999ExploitThird Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1
FAQ
What is CVE-2019-10999?
CVE-2019-10999 is a vulnerability with a CVSS score of 8.8 (HIGH). The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by pr...
How severe is CVE-2019-10999?
CVE-2019-10999 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10999?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dcs-930L Firmware, Dlink Dcs-930L, Dlink Dcs-931L Firmware, Dlink Dcs-931L, Dlink Dcs-932L Firmware.