D-Link Forums

The Graveyard - Products No Longer Supported => IP Cameras => DCS-932L => Topic started by: peterd on March 16, 2015, 10:36:56 AM

Title: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload
Post by: peterd on March 16, 2015, 10:36:56 AM
In case you haven't heard...

http://www.kb.cert.org/vuls/id/377348

D-Link has a firmware update available for the affected version.
Title: Re: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload
Post by: acellier on March 16, 2015, 10:44:34 AM
The linked article cites the vulnerability in firmware v1.04, used on hardware v1, then strangely says "According to D-Link's security advisory, users should update the firmware for affected device to version 2.0.17-b62"
... which would only be for hardware v2, right?
Title: Re: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload
Post by: peterd on March 16, 2015, 10:56:15 AM
I did find that odd too....  D-Link's site actually has firmware downloads for hardware revision A and B:

http://support.dlink.com/ProductInfo.aspx?m=DCS-932L
Title: Re: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload
Post by: FurryNutz on March 16, 2015, 11:26:58 AM
Rev B FW is not backwards compatible with Rev A HW.

The vulnerability is for v1.04 and prior version of FW. Anything past v1.04 should be now safe. The article is incorrect on it's statement about upgrading to v2.0x for Rev A cameras.

v1.10 just came out last week for Rev A
v2.01 just came out last week for Rev B for those users with Rev B cameras.

I recommend that you phone contact your regional D-Link support office and ask for help and information regarding this. We find that phone contact has better immediate results over using email.
Let us know how it goes please.
Title: Re: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload
Post by: acellier on March 16, 2015, 02:43:41 PM
I submitted comments to the CERT site.
Title: Re: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload
Post by: FurryNutz on March 16, 2015, 04:05:54 PM
Looks like it's been updated.  ;)
Title: Re: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload
Post by: RYAT3 on March 17, 2015, 07:22:17 AM
Upload to what exactly? SD card? Or OS?