RULE(RULE ID:338967)

Rule General Information
Release Date: 2025-05-20
Rule Name: D-Link DCS-930L Firmware Command Injection Vulnerability (CVE-2016-11021)
Severity:
CVE ID:
Rule Protection Details
Description: setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:39437
ExploitDB:39437
Solutions
Please contact the software vendor to update the software patch.