PT-2018-3876 · D Link · Dcs-825L

Published

2018-12-20

·

Updated

2023-04-26

·

CVE-2018-18442

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions D-Link DCS-825L version 1.08
Description The issue is related to insufficient input validation in the firmware of the D-Link DCS-825L network camera, which can be exploited by a remote attacker to cause a denial-of-service (DoS) condition. This can be achieved by sending a large number of specially crafted network packets, such as SYN flood, UDP flood, ICMP flood, or SYN-ACK flood attacks, thereby disrupting the device's availability, including live video and audio streaming.
Recommendations For D-Link DCS-825L version 1.08, consider restricting access to the device to minimize the risk of exploitation until a patch is available. As a temporary workaround, limiting the number of incoming network packets or implementing rate limiting on the network may help mitigate the risk of DoS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-02765
CVE-2018-18442

Affected Products

Dcs-825L