CVE-2026-13545: D-Link DCS-935L OS Command Injection Vulnerability
D-Link DCS-935L network cameras running firmware version 1.10.01 contain a critical flaw in their web configuration interface. An authenticated attacker can inject arbitrary operating system commands through the UID parameter in the setconf.cgi handler, gaining the ability to execute code with the privileges of the camera process. Because the vulnerability requires authentication but offers full system compromise once inside, it represents a high-severity risk for organizations relying on these devices for surveillance infrastructure.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-77, CWE-78
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-29 / 2026-06-30
NVD description (verbatim)
A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13545 is an OS command injection vulnerability in the POST parameter handler of D-Link DCS-935L firmware 1.10.01. The vulnerability exists in function sub_400E40 within setconf.cgi, where unsanitized user input from the UID parameter is passed to OS command execution routines. The CWEs involved (CWE-77: Improper Neutralization of Special Elements used in a Command, and CWE-78: Improper Neutralization of Special Elements used in an OS Command) confirm inadequate input validation and output encoding. An authenticated attacker can craft a malicious POST request containing shell metacharacters in the UID field to break out of the intended command context and execute arbitrary code on the underlying Linux system.
Business impact
Compromise of a DCS-935L camera allows an attacker to pivot into the network segment where the device operates, potentially accessing stored video feeds, intercepting real-time streams, or using the compromised device as a foothold for lateral movement. For organizations deploying these cameras in secure or sensitive areas—data centers, offices, facilities—unauthorized access undermines physical security monitoring, creates compliance violations (HIPAA, GDPR, SOC2 if video data is involved), and damages trust in surveillance infrastructure. The authenticated nature of the attack means threat actors must first gain initial access, but insider threats or credential compromise could activate this risk.
Affected systems
D-Link DCS-935L network cameras with firmware version 1.10.01 are confirmed vulnerable. Organizations should verify their deployed camera firmware versions and confirm whether they have installed patches or firmware updates released by D-Link. Other DCS-935L firmware versions should be assessed against D-Link's advisory to determine their exposure status. No other D-Link camera models are confirmed affected by this specific vulnerability, though similar architectures in related models warrant review.
Exploitability
The vulnerability is remotely exploitable but requires valid authentication credentials—an attacker must have a legitimate user account or stolen credentials for the camera's web interface. Public disclosure of this vulnerability has occurred, and proof-of-concept details are available, increasing the likelihood of active exploitation. The relative simplicity of OS command injection (once authenticated) means the technical bar for weaponization is low. Organizations where camera credentials are weak, reused, or compromised face immediate risk.
Remediation
Apply the firmware update released by D-Link that addresses this vulnerability. Verify the patched firmware version against D-Link's official security advisory before deployment. In parallel, enforce strong, unique passwords for all camera administrative accounts, restrict network access to the camera's web interface using firewall rules or network segmentation, and disable remote management if not required. Monitor authentication logs for brute-force or credential-stuffing attempts targeting camera interfaces.
Patch guidance
Contact D-Link support or check their official security advisories to obtain the patched firmware version that resolves CVE-2026-13545. Firmware updates for network cameras should be deployed during maintenance windows to avoid disrupting surveillance. Test patches in a staging environment before production rollout. Document the firmware versions and deployment dates for audit compliance. Consider implementing a device firmware management policy that mandates security updates within 30 days of release for HIGH-severity issues.
Detection guidance
Monitor network traffic to DCS-935L devices for POST requests to setconf.cgi with suspicious or URL-encoded characters in the UID parameter (shell metacharacters such as semicolons, pipes, backticks, or command substitution syntax). Log and alert on failed authentication attempts to camera interfaces, especially repeated attempts suggesting credential attack. Enable logging on the camera itself if available, and review access logs for anomalous administrative activity following authentication. Network intrusion detection systems (IDS) should be configured with signatures for OS command injection patterns in HTTP requests targeting camera management interfaces.
Why prioritize this
Despite the authenticated requirement, this vulnerability scores HIGH (CVSS 8.8) because successful exploitation results in complete system compromise: an attacker gains code execution with full confidentiality, integrity, and availability impact. Public disclosure and available proof-of-concept code accelerate threat actor adoption. The vulnerability affects physical security infrastructure, making it attractive to sophisticated adversaries and insider threats. Organizations with these cameras deployed should prioritize patching after ensuring credentials are strong and access is restricted.
Risk score, explained
CVSS 3.1 score 8.8 (HIGH) reflects the combination of network-based attack vector, low attack complexity once inside, requirement for low privileges (authenticated user), and high impact across all three security dimensions (confidentiality, integrity, availability). The score appropriately captures the severity of unauthenticated OS command injection; the authentication requirement prevents a CRITICAL rating but does not materially reduce the impact once the barrier is breached. Organizations should treat this as a priority remediation candidate.
Frequently asked questions
Do I need valid camera credentials to exploit this vulnerability?
Yes. CVE-2026-13545 requires authentication to the camera's web interface. However, once an attacker has credentials—through password reuse, weak defaults, or credential compromise—the path to full system compromise is straightforward.
Is this vulnerability included in the CISA KEV catalog?
No, this vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, public disclosure and proof-of-concept availability suggest active exploitation is possible and may increase over time.
Which firmware versions of the DCS-935L are affected?
Firmware version 1.10.01 is confirmed vulnerable. Verify your camera's current firmware version in the device settings and consult D-Link's official security advisory to confirm which other versions are affected and which patches resolve the issue.
Can I mitigate this without patching immediately?
Partial mitigation is possible: disable remote access to the camera web interface, restrict access via firewall rules to trusted IP ranges, enforce strong unique passwords, and disable default accounts. However, these controls do not eliminate the vulnerability—patching remains the definitive remediation.
This analysis is provided for informational purposes and should not be considered official security advice. Patch version numbers and remediation timelines should be verified against D-Link's official security advisories and vendor documentation. Organizations are responsible for assessing their own risk and implementing appropriate controls. SEC.co makes no warranty regarding the completeness or accuracy of information related to vendor patches or timeline guidance. Consult with your security team and vendor support before deploying any changes to production infrastructure. Source: NVD (public-domain), retrieved 2026-08-08. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10214HIGHCommand Injection in chatgpt-on-wechat Bash Tool
- CVE-2026-10219HIGHGoClaw Command Injection Vulnerability
- CVE-2026-10273HIGHRemote Code Execution in php-censor Webhook Handler
- CVE-2026-10870HIGHShibby Tomato 1.28.0000 OS Command Injection Vulnerability
- CVE-2026-10871HIGHShibby Tomato Remote Command Injection via IPv6 6rd Parameter
- CVE-2026-10872HIGHOS Command Injection in Shibby Tomato 1.28.0000 Web UI
- CVE-2026-10873HIGHOS Command Injection in Shibby Tomato 1.28.0000 Web UI
- CVE-2026-11556HIGHTenda F451 Command Injection Vulnerability (CVSS 8.8)