CVE-2016-11021: D-Link DCS-930L Devices OS Command Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 68.9% chance of exploitation in the next 30 days.

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

Affected products

  • D-Link DCS-930L Firmware: before 2.12 (fixed in 2.12)

Published 2020-03-09. Last modified 2026-06-17.