CameraRisk

CVE-2016-11021

D-Link · exploited in the wild

Published
9 March 2020
Last modified
17 June 2026
CVSS
7.2 v3.1
Severity
high
EPSS
68.9% (99th pct)
CISA KEV
Added 25 March 2022 KEV
NVD status
Analyzed
Weaknesses
CWE-78

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

Exploitation

Added to the CISA Known Exploited Vulnerabilities catalogue on 25 March 2022, with a remediation due date of 15 April 2022 for US federal civilian agencies. CISA records no known ransomware campaign use.

Required action as published by CISA: The impacted product is end-of-life and should be disconnected if still in use.

Affected products

ProductVendorTypeVersions named
DCS-930L D-Link IP camera 1.15.04, < 2.12, <= 1.15.04, <= 2.13.15 +2

References

CVE-2016-11021 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.