PT-2018-3876 · D Link · Dcs-825L
Published
2018-12-20
·
Updated
2023-04-26
·
CVE-2018-18442
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DCS-825L version 1.08
Description
The issue is related to insufficient input validation in the firmware of the D-Link DCS-825L network camera, which can be exploited by a remote attacker to cause a denial-of-service (DoS) condition. This can be achieved by sending a large number of specially crafted network packets, such as SYN flood, UDP flood, ICMP flood, or SYN-ACK flood attacks, thereby disrupting the device's availability, including live video and audio streaming.
Recommendations
For D-Link DCS-825L version 1.08, consider restricting access to the device to minimize the risk of exploitation until a patch is available. As a temporary workaround, limiting the number of incoming network packets or implementing rate limiting on the network may help mitigate the risk of DoS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dcs-825L