← back
CVE-2026-1419

D-Link DCS700l Web Form setDayNightMode command injection

CVSS 5.1 MEDIUMEPSS 15.1%CWE-74CWE-77
Vexday Risk Score
18Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 15.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DCS700l

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →