• Home Support Forums Security Advisories Shop     English | French
Support Announcement
DCS-931L/DCS-932L/DCS-933L/DCS-934L/DCS-5009L/DCS-5010L/DCS-5020L/DCS-5025L :: CVE-2017-17020 :: Authenticated RCE vulnerability

 

Overview  

 

On November 22, 2017, D-Link became  aware that a 3rd party researcher has recently disclosed CVE-2017-17720 that accused DCS-5020L of several security vulnerabilities.

 

Upon investigation, D-Link verified the report and expanded the scope to other models including DCS-5025L, DCS-932L, DCS-5009L, DCS-5010L, DCS-5020L, DCS-931L, DCS-933L, and the DCS-934L

 

D-Link takes the issues of network security and user privacy very seriously. We have a dedicated task force and product management team on call to address evolving security issues and implement appropriate security measures. 

   

Disclosure   

 

     3rd party researcher
     Tim Carrington ::  Tim@fidusinfosec.com

 

     CVE-2017-17720

     https://fidusinfosec.com/dlink-dcs-5030l-remote-code-execution-cve-2017-17020/

     https://nvd.nist.gov/vuln/detail/CVE-2017-17020

     https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17020

   
Affected Products

 

Currently, D-Link is aware that the following D-Link brand devices may be affected:

 

Model HW Rev. Affected FW Fixed FW Recommendation Info Last Update
DCS-931L All HW Rev A v1.14.11 and below v1.15.01 Use mydlink Lite Mobile App to update 11/11/2019
DCS-932L All HW Rev B v2.17.01 and below v2.18.01 Use mydlink Lite Mobile App to update 11/11/2019
DCS-933L All HW Rev A v1.14.11 and below v1.15.01 Use mydlink Lite Mobile App to update 11/11/2019
DCS-934L  All HW Rev A  v1.06.02 and below  v1.07.01  Use mydlink Lite Mobile App to update
11/11/2019
DCS-5009L  All HW Rev A v1.09.12 and below  v1.1001 Use mydlink Lite Mobile App to update 11/11/2019
DCS-5010L  All HW Rev A  v1.15.12 and below  v1.16.01  Use mydlink Lite Mobile App to update 11/11/2019
DCS-5020L   All HW Rev A  v1.15.12 and below v1.16.01   Use mydlink Lite Mobile App to update 11/11/2019
DCS-5025L  All HW Rev A v1.03.07 and below  v1.04.02 Use mydlink Home or Lite App to update 11/11/2019

 
 

Recommendations


To mitigate the risks, we strongly encourage our users to do the following:

 

     - Ensure you have checked your local customer care support site (In US: support.dlink.com) to get the latest firmware available for your device.

 

 

Security patch for your D-Link Devices


This firmware is an update security vulnerabilities in affected D-Link devices. D-Link will update this continually and we strongly recommend all users to install this relevant updates.

 

As there are different hardware revisions on our products, please check this on your device before downloading the correct corresponding firmware update. The hardware revision information can usually be found on the product label on the underside of the product next to the serial number. Alternatively, they can also be found on the device web configuration.