A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.
Advisories

No advisories yet.

Fixes

Solution

D-Link has released a security advisory and a software update for the affected camera model. Please visit this D-Link Security Announcement https://supportannouncement.us.dlink.com/security/publication.aspx  for further information.D-Link strongly urges all users to install the relevant updates and regularly check for further updates. After downloading the software update, it is essential to ALWAYS validate its success by comparing the software version on your product interface to the software update version. The model number listed in this advisory is known only for D-Link India Limited. Users of cameras produced by the other listed vendors are encouraged to evaluate this vulnerability within their environment.


Workaround

No workaround given by the vendor.

History

Thu, 11 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dcs-f5614-l1
Vendors & Products D-link
D-link dcs-f5614-l1

Wed, 10 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Title D-Link CCTV camera model DCS-F5614-L1 Missing Authentication for Critical Function
References

Wed, 10 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Description A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-12-11T19:00:24.673Z

Reserved: 2025-11-24T14:53:22.497Z

Link: CVE-2025-13607

cve-icon Vulnrichment

Updated: 2025-12-11T18:29:11.040Z

cve-icon NVD

Status : Received

Published: 2025-12-10T18:16:18.157

Modified: 2025-12-10T21:16:03.603

Link: CVE-2025-13607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-10T21:33:12Z

Weaknesses