CVE-2013-1601 is an information disclosure vulnerability affecting numerous D-Link IP camera models, including the WCS-1100, DCS-2121, and DCS-1100 series. The flaw lies in the lums.cgi script's failure to restrict access to live video streams, potentially allowing unauthorized users to obtain sensitive video information. Rated Medium severity with a CVSS score of 5.3, this vulnerability is easily exploitable over the network without authentication, leading to a loss of confidentiality. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-25138) exists, and it has garnered significant community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-3411_firmware:1.02:*:*:*:*:*:*:* | ||
1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-3430_firmware:1.02:*:*:*:*:*:*:* | ||
1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5605_firmware:1.01:*:*:*:*:*:*:* | ||
1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5635_firmware:1.01:*:*:*:*:*:*:* | ||
1.04CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-1100l_firmware:1.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.