CVE-2026-12174: D-Link DCS-935L Format String Vulnerability
D-Link DCS-935L cameras running firmware version 1.10.01 contain a format string vulnerability in their web interface. An attacker with valid login credentials can send specially crafted requests to a specific CGI handler to read sensitive memory, modify system behavior, or execute code on the device. The vulnerability requires authentication but offers no other barriers; it can be exploited over the network without user interaction.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-119, CWE-134
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-13 / 2026-06-17
NVD description (verbatim)
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
A format string flaw exists in the snprintf function within the HTTP handler component at /web/cgi-bin/greece/rhea on D-Link DCS-935L firmware 1.10.01. Format string vulnerabilities occur when user-supplied data is passed directly as a format string argument, allowing attackers to read arbitrary memory (information disclosure) or write to arbitrary memory (code execution). The affected code path processes user input without proper sanitization, and the network-accessible CGI handler means the attack surface spans any network with access to the camera's web interface. CWE-119 (buffer overflow) and CWE-134 (use of externally-controlled format string) are the underlying weaknesses.
Business impact
Compromised DCS-935L cameras become a foothold into physical security infrastructure. An authenticated attacker gains the ability to exfiltrate stored credentials, surveillance data, or system configuration; modify camera behavior (disable recording, alter feeds); or pivot to other network segments. Organizations relying on these cameras for premises monitoring face potential loss of video evidence, unauthorized access to restricted areas, and supply-chain infection risks if cameras are deployed in sensitive environments.
Affected systems
D-Link DCS-935L IP camera models running firmware version 1.10.01 are confirmed vulnerable. Organizations should inventory all instances of this model and firmware version in their environment. Verify exact firmware versions via the camera's web interface (typically accessible at the device's IP address). The vulnerability applies only to this specific firmware version; confirm whether patches for newer versions are available from D-Link.
Exploitability
The vulnerability requires valid credentials to exploit, placing it beyond unauthenticated attack reach. However, default credentials, weak passwords, or compromised accounts are common in IoT deployments, making credential acquisition a realistic precursor attack. Public disclosure of the vulnerability means exploitation techniques and proof-of-concept code are available; defensive time is limited. Overall exploitability is moderate-to-high given the prevalence of weak credential hygiene in camera deployments.
Remediation
Patch the affected firmware to a patched version released by D-Link (verify current patch availability in D-Link's official security advisories). If no patch exists, implement network segmentation to restrict access to the camera's web interface to trusted administrative networks only. Enforce strong, unique passwords on camera accounts. Monitor for suspicious authentication patterns or memory read/write attempts. Consider replacing vulnerable units if vendor support has ended and patches remain unavailable.
Patch guidance
Check D-Link's product security page for DCS-935L firmware updates released after June 2026. Download patches only from D-Link's official download center or security advisories to avoid supply-chain injection. Before deploying patches in production, test on a non-critical camera instance to verify functionality and network integration. Patch deployment should be coordinated to minimize surveillance gaps in critical areas. Document the firmware version before and after patching for compliance and audit purposes.
Detection guidance
Monitor network traffic to DCS-935L devices for POST requests to /web/cgi-bin/greece/rhea with unusual or repeated format string payloads (strings containing %x, %n, or similar format specifiers). Log authentication events to the camera's web interface and flag login attempts from unexpected IP ranges or with failed authentication followed by success. Inspect device syslog or event logs (if accessible) for errors or warnings originating from the HTTP handler. Intrusion detection systems should detect format string exploitation attempts if signatures are available.
Why prioritize this
The CVSS 3.1 score of 8.8 (HIGH) reflects high confidentiality, integrity, and availability impact for authenticated attackers. Public disclosure combined with low attack complexity elevates practical risk. Physical security cameras are often targets for espionage, blackmail, or lateral movement into corporate networks. Organizations should prioritize patching or isolating vulnerable cameras within 7–14 days, especially those in sensitive locations (boardrooms, data centers, executive offices).
Risk score, explained
The CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H assigns an 8.8 rating. Network accessibility (AV:N) and low attack complexity (AC:L) widen exposure. The requirement for low privileges (PR:L) reflects the authentication barrier, but does not prevent exploitation via weak credentials. High impact across confidentiality, integrity, and availability (C:H/I:H/A:H) stems from memory read/write primitives that enable data theft, privilege escalation, or denial of service. The score appropriately reflects the threat when authentication is compromised.
Frequently asked questions
Can this vulnerability be exploited without logging in to the camera?
No. The vulnerability requires valid credentials to the camera's web interface. However, many cameras are deployed with default credentials or weak passwords, making account compromise a realistic attack vector. Organizations should enforce strong, unique passwords and restrict access to camera interfaces.
Are other D-Link camera models affected?
The confirmed affected model is DCS-935L running firmware 1.10.01. Other D-Link camera models and firmware versions may have similar vulnerabilities. Review D-Link's security advisories for your specific models, and do not assume immunity based on similar product lines.
What should we do if we cannot patch immediately?
Implement network segmentation to restrict camera access to a dedicated, isolated VLAN. Disable remote access to the camera's web interface if not needed, and use a VPN or bastion host for administrative access. Monitor authentication logs and network traffic for exploitation attempts. Establish a patching timeline and document your interim controls.
How can we verify if our camera is vulnerable?
Log into your camera's web interface, navigate to the system settings or about page, and confirm the firmware version. If it is 1.10.01, your device is vulnerable. Check D-Link's security advisories to confirm patch availability for your region or firmware variant, as release schedules may vary.
This analysis is based on information published as of June 2026. Vulnerability details, patch availability, and affected versions may change; verify current vendor advisories before taking action. No exploit code or weaponized proof-of-concept techniques are provided in this analysis. Organizations should assess their specific environment, backup criticality, and change management procedures before deploying patches. SEC.co makes no warranty regarding the accuracy, completeness, or timeliness of this information and disclaims liability for actions taken or not taken in reliance upon it. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10270HIGHD-Link DI-7001 MINI Stack-Based Buffer Overflow in httpd_debug.asp
- CVE-2026-10062HIGHTRENDnet TEW-432BRP Stack Overflow – EOL Hardware Risk
- CVE-2026-10063HIGHTRENDnet TEW-432BRP Stack Overflow – End-of-Life Router Vulnerability
- CVE-2026-10065HIGHShibby Tomato 1.28 Stack Buffer Overflow in tomatodata.cgi
- CVE-2026-10066HIGHShibby Tomato Stack Buffer Overflow in UPS Service (RCE)
- CVE-2026-10067HIGHShibby Tomato 1.28 Stack Buffer Overflow in multimon.cgi
- CVE-2026-10119HIGHStack Overflow in TRENDnet TEW-432BRP End-of-Life Router
- CVE-2026-10120HIGHTRENDnet TEW-432BRP Buffer Overflow – No Patch Available