Monday 13 May 2019, Poradnik bezpieczeństwa

Vulnerability in D-Link surveillance camera

Lost24

Security experts have shown that the surveillance camera manufactured by D-Link, model: DCS-2132L, has security gaps. This is disturbing mainly because people who invested in the security of their homes in the form of a surveillance camera may have been exposed to cybercriminals. Security vulnerabilities have enabled third parties to tap into video stream.


Experts from ESET have shown that the camera did not encrypt the device-cloud-user app line of communication. In this way, the cybercriminal could intercept the feed from the camera. It has been proven that in addition to image capture, it was also possible to get a real time preview of the audio recorded by the camera. The fault of this is the improperly secured myDlink web-browser plugin.


D-Link removed the defective browser plugin, however, the problem with the encryption of cloud communication still remains.