CVE-2026-36983

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

high 7.3 CVSS 3.1
Published: May 11, 2026
Modified: May 12, 2026
Vendor: Dlink
Product: Dcs-932L Firmware
Versions: 2.18.01

Description

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

References

Related CVEs