A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 30 Jan 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dcs-700l
Dlink dcs-700l Firmware
CPEs cpe:2.3:h:dlink:dcs-700l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-700l_firmware:1.03.09:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dcs-700l
Dlink dcs-700l Firmware

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dcs700l
Vendors & Products D-link
D-link dcs700l

Mon, 26 Jan 2026 04:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title D-Link DCS700l Web Form setDayNightMode command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-01-26T15:11:20.874Z

Reserved: 2026-01-25T14:14:29.866Z

Link: CVE-2026-1419

cve-icon Vulnrichment

Updated: 2026-01-26T15:11:16.407Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-26T05:16:05.193

Modified: 2026-01-30T16:50:43.490

Link: CVE-2026-1419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-26T11:47:53Z

Weaknesses