CVE-2026-1532
low-risk
Published 2026-01-28
A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the component Music File Upload Service. The manipulation of the argument UploadMusic leads to path traversal. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Do I need to act?
-
0.02% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
2
CVSS 2.4/10
Low
ADJACENT_NETWORK
/ LOW complexity
Affected Products (1)
Dcs-700L Firmware
Affected Vendors
References (5)
Permissions Required
https://vuldb.com/?ctiid.343218
Third Party Advisory
https://vuldb.com/?id.343218
Third Party Advisory
https://vuldb.com/?submit.738693
Product
https://www.dlink.com/
15
/ 100
low-risk
Severity
10/34 · Low
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal