header-logo
Suggest Exploit
vendor:
DCS Series Cameras
by:
SlidingWindow
8,8
CVSS
HIGH
Insecure CrossDomain.XML
352
CWE
Product Name: DCS Series Cameras
Affected Version From: DCS-933L with firmware version 1.03
Affected Version To: DCS-933L with firmware version 1.03
Patch Exists: YES
Related CWE: CVE-2017-7852
CPE: h:d-link:dcs-933l
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017

Insecure CrossDomain.XML in D-Link DCS Series Cameras

D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device's settings.

Mitigation:

D-Link has released a firmware update to address this vulnerability.
Source

Exploit-DB raw data: