CVE-2026-36983: D-Link Dcs-932l Firmware

High severity, CVSS 7.3. EPSS: 2.3% chance of exploitation in the next 30 days.

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

Affected products

  • D-Link Dcs-932l Firmware: version 2.18.01 only

Published 2026-05-11. Last modified 2026-06-17.