CVE-2017-17020 describes a critical command injection vulnerability in D-Link DCS-5009, DCS-5010, and DCS-5020L IP cameras, specifically within the alphapd binary. This flaw allows remote authenticated attackers to execute arbitrary code by manipulating the AdminID field during system administration settings. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability compromise. While not listed on CISA's KEV catalog, a Proof-of-Concept exploit is publicly available on ExploitDB, indicating its exploitability, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.08.11CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5009_firmware:*:*:*:*:*:*:*:* | ||
<= 1.14.09CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5010_firmware:*:*:*:*:*:*:*:* | ||
<= 1.14.09CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5020l_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.