Description
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.
Published: 2017-04-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-16827 D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.
History

No history.

Subscriptions

Dlink Dcs-2132l Dcs-2132l Firmware Dcs-2136l Dcs-2136l Firmware Dcs-2210l Dcs-2210l Firmware Dcs-2230l Dcs-2230l Firmware Dcs-2310l Dcs-2310l Firmware Dcs-2330l Dcs-2330l Firmware Dcs-2332l Dcs-2332l Firmware Dcs-2530l Dcs-2530l Firmware Dcs-5000l Dcs-5000l Firmware Dcs-5009l Dcs-5009l Firmware Dcs-5010l Dcs-5010l Firmware Dcs-5020l Dcs-5020l Firmware Dcs-5025l Dcs-5025l Firmware Dcs-5029l Dcs-5029l Firmware Dcs-5030l Dcs-5030l Firmware Dcs-5222l Dcs-5222l Firmware Dcs-6010l Dcs-6010l Firmware Dcs-6212l Dcs-6212l Firmware Dcs-7000l Dcs-7000l Firmware Dcs-7010l Dcs-7010l Firmware Dcs-930l Dcs-930l Firmware Dcs-931l Dcs-931l Firmware Dcs-932l Dcs-932l Firmware Dcs-933l Dcs-933l Firmware Dcs-934l Dcs-934l Firmware Dcs-942l Dcs-942l Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T16:19:28.376Z

Reserved: 2017-04-13T00:00:00.000Z

Link: CVE-2017-7852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-04-24T10:59:00.160

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-7852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses