← Vulnerability feed

Vulnerability record · CVE-2015-2048 · published 23 February 2015

CVE-2015-2048: Dlink dcs-931l firmware cross-site request forgery vulnerability

Dlink · Dcs 931l Firmware

Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

6.8 CVSS 2.0 Medium EPSS 0.93% · top 40.9% CWE-352 · Cross-site request forgery
6.8CVSS 2.0 base score
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2048 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2015-2049D-Link DCS-931L unrestricted file upload enables remote code executionD-Link DCS-931L firmware 1.04 and earlier permits an authenticated user to upload a file with an executable extension, which the device then executes…EPSS 67%analysed8.8CVE-2019-10999Dlink dcs-930l firmware out-of-bounds write vulnerabilityThe D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely aut…EPSS 3.6%8.8CVE-2017-7852Dlink dcs-2230l firmware cross-site request forgery vulnerabilityD-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's s…EPSS 4.3%7.3CVE-2026-2260Dlink dcs-931l firmware command injection vulnerabilityA vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argu…EPSS 5.2%2.0CVE-2026-2227Dlink dcs-931l firmware injection vulnerabilityA vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation o…EPSS 6.1%9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed8.1CVE-2008-4128Cisco IOS HTTP Administration CSRF allows arbitrary command executionThe HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws.…KEVEPSS 34%analysed8.8CVE-2023-2533PaperCut NG/MF CSRF allows admin security setting changes and code executionPaperCut NG and MF contain a cross-site request forgery flaw that, under specific conditions, lets an attacker change security settings or execute ar…KEVEPSS 29%analysed

Source: NIST National Vulnerability Database (record CVE-2015-2048), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.