CVE-2013-1599 describes a critical command injection vulnerability in the /var/www/cgi-bin/rtpd.cgi script of numerous D-Link IP camera models, allowing remote attackers to execute arbitrary commands via the web interface. With a CVSS score of 9.8 (Critical), this vulnerability requires no authentication or user interaction and can lead to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, an ExploitDB entry exists, and its high EPSS score and community discussion indicate a significant potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-3411_firmware:1.02:*:*:*:*:*:*:* | ||
1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-3430_firmware:1.02:*:*:*:*:*:*:* | ||
1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5605_firmware:1.01:*:*:*:*:*:*:* | ||
1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5635_firmware:1.01:*:*:*:*:*:*:* | ||
1.04CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-1100l_firmware:1.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.