← Vulnerability feed

Vulnerability record · CVE-2021-41504 · published 24 September 2021

CVE-2021-41504: Dlink dcs-932l firmware vulnerability

Dlink · Dcs 932l Firmware

An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

8.0 CVSS 3.1 High EPSS 0.49% · top 60.2%
8.0CVSS 3.1 base score, v2 5.2
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41504 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-10999Dlink dcs-930l firmware out-of-bounds write vulnerabilityThe D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely aut…EPSS 3.6%8.8CVE-2017-7852Dlink dcs-2230l firmware cross-site request forgery vulnerabilityD-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's s…EPSS 4.3%8.7CVE-2025-5572Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability is the function setSystemEmail…EPSS 5.8%8.7CVE-2025-4843Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. This affects the function SubUPnPCSInit of the file /sbin/u…EPSS 1.3%8.7CVE-2025-4841Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01 and classified as critical. Affected by this issue is the function sub_404780 of the file /bin/g…EPSS 1.3%8.7CVE-2025-4842Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. This vulnerability affects the function isUCPCameraNameChange…EPSS 1.3%8.0CVE-2021-41503Dlink dcs-932l firmware improper authentication vulnerabilityDCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command int…EPSS 0.45%7.5CVE-2018-18441D-link dcs-936l firmware information exposure vulnerabilityD-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, suc…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2021-41504), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.