vendor:
DCS-900
by:
miscname.com
7.5
CVSS
HIGH
Configuration Vulnerability
16
CWE
Product Name: DCS-900
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: h:d-link:dcs-900
Platforms Tested:
Unknown
Change IP Address on D-Link DCS-900 Cameras without Authentication
This exploit allows an attacker to change the IP address on all D-Link DCS-900 cameras on the local network without authentication. The cameras use a broadcast/listen method of configuration and listen for a UDP broadcast packet to set their IP address. By sending a modified packet, an attacker can set the IP address of all listening cameras to a desired value.
Mitigation:
Update the firmware of the affected cameras to fix this vulnerability. Additionally, restrict access to the cameras' network to trusted devices only.