CVE-2026-13545Disclosure(dlink / dcs-935l)

LOWCVSS 7.4 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dcs-935l
  • dcs-935l_firmware

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-07-20)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
dcs-935ldcs-935l_firmware

2 versions affected across 2 products

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-06-28: 1Mentions · 2026-06-30: 1Mentions · 2026-07-20: 5Technical Details · 2026-06-30: 1Technical Details · 2026-07-20: 306-2806-3007-20
Signal classification2 categories
Disclosure
457.1%
General
342.9%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-281
Disclosure1
2026-06-301
Disclosure1
2026-07-205
Disclosure2General3
Full discourse7 posts
  • YogSotho@YogSoth0
    Disclosure

    #CVE-2026-13545 — #D-Link DCS-935L #Exploit Kit ## Identifier Summary - CVE ID: CVE-2026-13545 - Affected device: D-Link DCS-935L HD Wi-Fi Camera - Affected firmware: 1.10.01 (Build 20161128) - Vulnerability class: OS command injection / input-trust failure - Impact: Authenticated or adjacent RCE with root-equivalent device impact #0days #cybersecurity #hacking #security #CVSS #infosec #antisec

    Post summary

    The post announces a new CVE for the D‑Link DCS‑935L camera, detailing an OS command injection that allows authenticated or adjacent remote code execution with root‑equivalent impact.

    1101271.2K
    1.9K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Vendor v1.10.01. Source: X search for RCE 2026 exploit Posted: 2026-06-30T00:16:55.000Z Likes: 12 #CVE-2026-13545 — #D-Link DCS-935L #Exploit Kit Identifier Summary CVE ID: CVE-2026-13545 Affected device: D-Link DCS-935L HD Wi-Fi Camera Affected firmware: 1.10.01…

    Post summary

    The post mentions CVE‑2026‑13545 affecting a D‑Link camera firmware but gives only superficial information, lacking evidence of exploitation, patching, or technical details.

    1101182
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Source: X search for RCE 2026 exploit Posted: 2026-06-30T00:16:55.000Z Likes: 12 #CVE-2026-13545 — #D-Link DCS-935L #Exploit Kit Identifier Summary CVE ID: CVE-2026-13545 Affected device: D-Link DCS-935L HD Wi-Fi Camera Affected firmware: 1.10.01 (Build 20161128)…

    Post summary

    The tweet merely announces CVE‑2026‑13545’s existence with device and firmware details, offering no evidence of exploitation, patching, or a PoC.

    1101169
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Identifier Summary CVE ID: CVE-2026-13545 Affected device: D-Link DCS-935L HD Wi-Fi Camera Affected firmware: 1.10.01 (Build 20161128) Vulnerability class: OS command injection / input-trust failure Impact:

    Post summary

    The text announces CVE-2026-13545, detailing the affected D-Link DCS‑935L camera firmware and classifying the issue as OS command injection, but does not provide PoC, exploit code, or patch information.

    1101150
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-13545: #CVE-2026-13545 — #D-Link DCS-935L #Exploit Kit Identifier Summary CVE ID: CVE-2026-13545 Affected device: D-Link DCS-935L HD Wi-Fi Camera Affected firmware: 1.10.01 (Build 20161128) Vulnerability class: OS command injection / input-trust failure Impact:…

    Post summary

    The post announces a new OS command injection vulnerability in the D‑Link DCS‑935L camera firmware (1.10.01), listing affected device details but providing no PoC, exploit, or patch information.

    1001093
    320 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-13545. Source: X search for RCE 2026 exploit Posted: 2026-06-30T00:16:55.000Z Likes: 12

    Post summary

    A brief mention of CVE-2026-13545 with no additional details on exploitation, patches, or technical specifics.

    1000067
    326 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for D-Link DCS-935L (CVE-2026-13545) https://vuldb.com/vuln/374553

    Post summary

    A severe vulnerability, CVE-2026-13545, was disclosed for the D-Link DCS-935L, with only a reference to a VULDB entry and no additional PoC, exploit, or mitigation information.

    00000129
    2.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdcs-935l---
OSdlinkdcs-935l_firmware1.10.01--

Explore more