A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
History

Fri, 30 Jan 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dcs-700l
Dlink dcs-700l Firmware
CPEs cpe:2.3:h:dlink:dcs-700l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-700l_firmware:1.03.09:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dcs-700l
Dlink dcs-700l Firmware

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dcs700l
Vendors & Products D-link
D-link dcs700l

Mon, 26 Jan 2026 04:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title D-Link DCS700l Web Form setDayNightMode command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-01-26T04:32:08.759Z

Updated: 2026-01-26T15:11:20.874Z

Reserved: 2026-01-25T14:14:29.866Z

Link: CVE-2026-1419

cve-icon Vulnrichment

Updated: 2026-01-26T15:11:16.407Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-26T05:16:05.193

Modified: 2026-01-30T16:50:43.490

Link: CVE-2026-1419

cve-icon Redhat

No data.