Back

CVE-2017-11563

CRITICAL

D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP "Discover" service, which provides multiple functions such as changing the passwords and getting basic information, was installed on the device. A remote attacker can send a crafted UDP request to finderd to perform stack overflow and execute arbitrary code with root privilege on the device.

Published: Aug 24, 2018 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
dlink eyeon_baby_monitor_firmware 1.08.1

GitHub Security Advisory GHSA-w5w8-832m-w2m4

D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP ...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.20%

Top 8% most likely to be exploited

Threat Score 40.8 / 100

Data Sources

NVD EPSS GitHub