CVE-2017-7851: D-Link Dcs-936l
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.
Affected products
- D-Link Dcs-936l: before 1.05.07 (fixed in 1.05.07)
Published 2017-11-15. Last modified 2026-06-17.