← Vulnerability feed

Vulnerability record · CVE-2025-5571 · published 4 June 2025

CVE-2025-5571: Dlink dcs-932l firmware command injection vulnerability

Dlink · Dcs 932l Firmware

A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSystemAdmin. The manipulation of the argument AdminID leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

5.3 CVSS 4.0 Medium EPSS 14% · top 3.7% CWE-77 · Command injectionCWE-78 · OS command injection
5.3CVSS 4.0 base score, v2 6.5
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSystemAdmin. The manipulation of the argument AdminID leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_42/42.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.311028 Permissions RequiredVDB Entry
https://vuldb.com/?id.311028 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.588465 Third Party AdvisoryVDB Entry
https://www.dlink.com/ Product

Track CVE-2025-5571 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-10999Dlink dcs-930l firmware out-of-bounds write vulnerabilityThe D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely aut…EPSS 3.6%8.8CVE-2017-7852Dlink dcs-2230l firmware cross-site request forgery vulnerabilityD-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's s…EPSS 4.3%8.7CVE-2025-5572Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability is the function setSystemEmail…EPSS 5.8%8.7CVE-2025-4843Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. This affects the function SubUPnPCSInit of the file /sbin/u…EPSS 1.3%8.7CVE-2025-4841Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01 and classified as critical. Affected by this issue is the function sub_404780 of the file /bin/g…EPSS 1.3%8.7CVE-2025-4842Dlink dcs-932l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. This vulnerability affects the function isUCPCameraNameChange…EPSS 1.3%8.0CVE-2021-41503Dlink dcs-932l firmware improper authentication vulnerabilityDCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command int…EPSS 0.45%8.0CVE-2021-41504Dlink dcs-932l firmware vulnerabilityAn Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices comm…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2025-5571), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.