Home

Description

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

PUBLISHED Reserved 2026-04-06 | Published 2026-05-11 | Updated 2026-05-11 | Assigner mitre

References

www.dlink.com/en/security-bulletin/

github.com/fru1ts/IoT_vul/blob/main/D-Link/DCS-932L.md

cve.org (CVE-2026-36983)

nvd.nist.gov (CVE-2026-36983)

Download JSON