CVE-2017-11564
HIGHD-Link EyeOn Baby Monitor DCS-825L <1.08.1 - Command Injection
Title source: llmDescription
The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework. An attacker can forge malicious HTTP requests to execute commands; authentication is required before executing the attack.
References (2)
Core 2
Core References
Technical Description, Third Party Advisory x_refsource_misc
https://documents.trendmicro.com/assets/tech_brief_Device_Vulnerabilities_in_the_Connected_Home2.pdf
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Aug/19
Scores
CVSS v3
8.8
EPSS
0.0271
EPSS Percentile
86.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (1)
dlink/eyeon_baby_monitor_firmware
1.08.1
Published
Aug 24, 2018
Tracked Since
Feb 18, 2026