CVE-2017-11563: D-Link Eyeon Baby Monitor Firmware

Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.

D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP "Discover" service, which provides multiple functions such as changing the passwords and getting basic information, was installed on the device. A remote attacker can send a crafted UDP request to finderd to perform stack overflow and execute arbitrary code with root privilege on the device.

Affected products

  • D-Link Eyeon Baby Monitor Firmware: version 1.08.1 only

Published 2018-08-24. Last modified 2026-06-17.