Dcnetworks manufactures a line of embedded media and network appliances centered on the DCME-320 platform, which operates in broadcast and content-delivery environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate on command injection, OS command injection, and unrestricted file upload weaknesses that are characteristic of appliance interfaces with insufficient input validation and access controls. Defenders should prioritize patching these devices, particularly internet-exposed instances; live severity, exploitation, and coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dcnetworks over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9387CRITICAL A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Manag | Aug 24, 2025 | 9.8 | 35 | NO | NO |
CVE-2026-2000HIGH A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Ba | Feb 6, 2026 | 7.2 | 33 | NO | NO |
CVE-2024-52779CRITICAL DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10. | Nov 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-48659CRITICAL An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component. | Oct 21, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-51115CRITICAL DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability. | Nov 5, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-52781CRITICAL DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/tool/traceroute.php. | Nov 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-52780CRITICAL DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/mgmt_edit.php. | Nov 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-52778CRITICAL DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist.p | Nov 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-52777CRITICAL DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/license_update.php. | Nov 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-52782CRITICAL DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist_n | Nov 29, 2024 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dcnetworks.
Media articles that mention a CVE ID that affects a product developed by Dcnetworks — matched by CVE ID, not by vendor name.