The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework. An attacker can forge malicious HTTP requests to execute commands; authentication is required before executing the attack.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://documents.trendmicro.com/assets/tech_brief_Device_Vulnerabilities_in_the_Connected_Home2.pdf | third party advisory technical description |
http://seclists.org/fulldisclosure/2018/Aug/19 | third party advisory mailing list |