CVE-2018-18767
HIGHD-Link myDlink Baby Camera Monitor - Inadequate Encryption Strength in Credential Transmission
Title source: llmDescription
An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://dojo.bullguard.com/dojo-by-bullguard/blog/i-got-my-eyeon-you-security-vulnerabilities-in-baby-monitor/
Scores
CVSS v3
7.0
EPSS
0.0017
EPSS Percentile
37.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-326
Status
published
Products (2)
d-link/dcs-825l_firmware
1.08
dlink/mydlink_baby_camera_monitor
2.04.06
Published
Dec 20, 2018
Tracked Since
Feb 18, 2026