Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-10999 PoC — 多款D-Link产品缓冲区错误漏洞

Source
Associated Vulnerability
Title: 多款D-Link产品缓冲区错误漏洞 (CVE-2019-10999)
Description:The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).
Description
Full exploit for D-Link DCS-5020L, POC crash for others that are vulnerable as well. 
Readme
# D-Link Exploit
The exploit exists in the devices server, alphapd, when processing `wireless.htm` 
prior to displaying it to the user. If `WEPEncryption` is provided in the 
URL this leads to a buffer overflow if the value is longer than 0x28 bytes. A 
URL of the form:
 
     http://IP_ADDRESS/wireless.htm?WEPEncryption=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBBB

will exercise the exploit and begin executing at `0x42424242`. 

**Note: The exploit requires credentials to be successful.**
**Default credentials are admin with a blank password.**

## exploit.py
Full exploit that takes advantage of a buffer overflow in the alphapd server to 
execute an arbitrary command on the device. It has been tested on the DCS-5020L
with all available versions of the firmware as well as the most recent firmware
of the DCS-930L. More devices and versions can be added by reading the comments
in the [overflow](DlinkExploit/overflows/overflow.py) file. I might add more devices 
and versions as time permits, but it's not a high priority. The initial commit of
this project has some simpler Python2 examples. 

## Vulnerable Devices
Below is the list of devices effected by this exploit. All versions of the firmware
are currently vulnerable. 

**DCS-930L**

**DCS-931L**

**DCS-932L**

**DCS-933L**

**DCS-934L**

**DCS-5009L**

**DCS-5010L**

**DCS-5020L**

**DCS-5025L**

**DCS-5030L**


## Live Vulnerable Devices
https://www.shodan.io/search?query=Server%3A+alphapd

## Example Usage
This project is written in Python 3 and will not execute under Python 2.

`python3 exploit.py -i 192.168.0.100 -P 80 -u admin -p ""`

## In-depth Explaination
Video - https://www.youtube.com/watch?v=ijcbkY3dtso
Skip to 13:15 to hear about the actual exploit.


4 Part Blog 

  * [Part 1](https://fuzzywalls.github.io/exploits/dcs-5020l-vuln-asses-pt1.html)
  * [Part 2](https://fuzzywalls.github.io/exploits/dcs-5020l-vuln-asses-pt2.html)
  * [Part 3](https://fuzzywalls.github.io/exploits/dcs-5020l-vuln-asses-pt3.html)
  * [Part 4](https://fuzzywalls.github.io/exploits/dcs-5020l-vuln-asses-pt4.html)
  
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →