10
CVSSv2

CVE-2013-1599

Published: 28/01/2020 Updated: 27/04/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dcs-3411_firmware 1.02

dlink dcs-3430_firmware 1.02

dlink dcs-5605_firmware 1.01

dlink dcs-5635_firmware 1.01

dlink dcs-1100l_firmware 1.04

dlink dcs-1130l_firmware 1.04

dlink dcs-1100_firmware 1.03

dlink dcs-1100_firmware 1.04

dlink dcs-1130_firmware 1.03

dlink dcs-1130_firmware 1.04

dlink dcs-2102_firmware 1.05

dlink dcs-2121_firmware 1.05

dlink dcs-3410_firmware 1.02

dlink dcs-5230_firmware 1.02

dlink dcs-5230l_firmware 1.02

dlink dcs-6410_firmware 1.00

dlink dcs-7410_firmware 1.00

dlink dcs-7510_firmware 1.00

dlink wcs-1100_firmware 1.00

Exploits

Core Security - Corelabs Advisory corelabscoresecuritycom/ D-Link IP Cameras Multiple Vulnerabilities 1 *Advisory Information* Title: D-Link IP Cameras Multiple Vulnerabilities Advisory ID: CORE-2013-0303 Advisory URL: wwwcoresecuritycom/advisories/d-link-ip-cameras-multiple-vulnerabilities Date published: 2013-04-29 Date of l ...
Core Security Technologies Advisory - D-Link IP Cameras suffer from OS command injection, authentication, information leak, and hard-coded credential vulnerabilities ...

Github Repositories

Class project for testing the DLink-DCS-5009L

DLink-DCS-5009L Class project for testing the DLink-DCS-5009L Instruction Manuals: -wwwdlinkcom/-/media/Consumer_Products/DCS/DCS%205009L/Manual/DCS_5009L_A1_Manual_v1_00_WWpdf -wwwdlinkcom/-/media/Consumer_Products/DCS/DCS%205009L/DCS-5009L%20DS_FINALpdf Materials for class: -Laptops (everyone) -Kali Linux (everyone, download iso from wwwkaliorg/d

Exploit toolkit for old ip cameras. Inspired by Black Hat 2013 - Exploiting Network Surveillance Cameras Like a Hollywood Hacker

CamMander (CVE-2013-1599) Exploit toolkit for (old) IP Cameras Educational Purposes Only Inspired by Black Hat 2013 - Exploiting Network Surveillance Cameras Like a Hollywood Hacker talk by Craig Heffner This is a rootshell toolkit for an Old day targeting D-LINK and TRENDnet cameras In his talk he mentioned that these cameras would most likely be exploitable "3 year