D-Link DCS-8300LHV2 ONVIF Command Injection Remote Code Execution Vulnerability
CVE-2023-51625
8HIGH
Summary
A vulnerability has been identified in D-Link DCS-8300LHV2 IP cameras that allows network-adjacent attackers to execute arbitrary code. This arises due to improper validation of user-supplied strings in the ONVIF API's SetSystemDateAndTime command, which listens on TCP port 80. Although the application requires authentication, this mechanism can be bypassed, posing a significant risk. Exploiting this flaw enables attackers to run commands with root privileges, potentially compromising the affected device. For further details, reference the vendor advisory and associated ZDI alerts.
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published