QSearchQSearch

CVE-2021-41503

8.0 HIGH

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control

Published: 2021-09-24 · Last updated: 2026-06-17

Severity and scoring

CVSS
8.0 HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-287

Affected products

VendorProduct
d-linkdcs-5000l_firmware, dcs-932l_firmware
dlinkdcs-5000l_firmware, dcs-932l_firmware

Description

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-12174 A security vulnerability has been detected in D-Link DCS-935L 1.10.01 (8.8 HIGH)
  • CVE-2026-11555 A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006 (3.7 LOW)
  • CVE-2026-11497 A vulnerability has been found in D-Link DCS-5615 1.01.00 (5.3 MEDIUM)
  • CVE-2026-11492 A security flaw has been discovered in D-Link DIR-823G 1.0.2B05 (4.3 MEDIUM)
  • CVE-2026-11339 A vulnerability was detected in D-Link DWR-M920 up to 1.1.50 (6.3 MEDIUM)

Same CWE

  • CVE-2026-48780 Forem is open source software for building communities (8.2 HIGH)
  • CVE-2026-48114 Metacat is data repository software that helps researchers preserve, share, and discover data (9.8 CRITICAL)
  • CVE-2026-12183 Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerabili... (9.8 CRITICAL)
  • CVE-2026-50623 An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF (4.8 MEDIUM)
  • CVE-2026-48611 Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading t... (9.8 CRITICAL)