D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.
Conclusion & alert: CVE-2017-7852 is rated High Exploit Risk (72.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.50%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 42074 | exploit_db | edb | 2017-02-22 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-06 | 0.89% | 0.50% | -0.39% |
| 2 | 2026-02-17 | 1.00% | 0.89% | -0.12% |
| 3 | 2025-11-21 | — | 1.00% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| dlink | dcs-2230l_firmware | <= 1.03.01 | cpe:2.3:o:dlink:dcs-2230l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2310l_firmware | <= 1.08.01 | cpe:2.3:o:dlink:dcs-2310l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2332l_firmware | <= 1.08.01 | cpe:2.3:o:dlink:dcs-2332l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-6010l_firmware | <= 1.15.01 | cpe:2.3:o:dlink:dcs-6010l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-7010l_firmware | <= 1.08.01 | cpe:2.3:o:dlink:dcs-7010l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2530l_firmware | <= 1.00.21 | cpe:2.3:o:dlink:dcs-2530l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-930l_firmware | <= 1.15.04 | cpe:2.3:o:dlink:dcs-930l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-930l_firmware | <= 2.13.15 | cpe:2.3:o:dlink:dcs-930l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-932l_firmware | <= 1.13.04 | cpe:2.3:o:dlink:dcs-932l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-932l_firmware | <= 2.13.15 | cpe:2.3:o:dlink:dcs-932l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-934l_firmware | <= 1.04.15 | cpe:2.3:o:dlink:dcs-934l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-942l_firmware | <= 1.27 | cpe:2.3:o:dlink:dcs-942l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-942l_firmware | <= 2.11.03 | cpe:2.3:o:dlink:dcs-942l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-931l_firmware | <= 1.13.05 | cpe:2.3:o:dlink:dcs-931l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-933l_firmware | <= 1.13.05 | cpe:2.3:o:dlink:dcs-933l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5009l_firmware | <= 1.07.05 | cpe:2.3:o:dlink:dcs-5009l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5010l_firmware | <= 1.13.05 | cpe:2.3:o:dlink:dcs-5010l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5020l_firmware | <= 1.13.05 | cpe:2.3:o:dlink:dcs-5020l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5000l_firmware | <= 1.02.02 | cpe:2.3:o:dlink:dcs-5000l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5025l_firmware | <= 1.02.10 | cpe:2.3:o:dlink:dcs-5025l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5030l_firmware | <= 1.01.06 | cpe:2.3:o:dlink:dcs-5030l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2210l_firmware | <= 1.03.01 | cpe:2.3:o:dlink:dcs-2210l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2136l_firmware | <= 1.04.01 | cpe:2.3:o:dlink:dcs-2136l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2132l_firmware | <= 1.08.01 | cpe:2.3:o:dlink:dcs-2132l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-7000l_firmware | <= 1.04.00 | cpe:2.3:o:dlink:dcs-7000l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-6212l_firmware | <= 1.00.12 | cpe:2.3:o:dlink:dcs-6212l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5029l_firmware | <= 1.12.00 | cpe:2.3:o:dlink:dcs-5029l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2310l_firmware | <= 2.03.00 | cpe:2.3:o:dlink:dcs-2310l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2330l_firmware | <= 1.13.00 | cpe:2.3:o:dlink:dcs-2330l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-2132l_firmware | <= 2.12.00 | cpe:2.3:o:dlink:dcs-2132l_firmware:*:*:*:*:*:*:*:* |
| dlink | dcs-5222l_firmware | <= 2.12.00 | cpe:2.3:o:dlink:dcs-5222l_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.qualys.com/2017/02/22/qsa-2017-02-22/qsa-2017-02-22.pdf | Exploit Mitigation Third Party Advisory |