Multiple D-Link DCS Cameras contain a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered when a direct request is sent for /frame/GetConfigm, which may disclose configuration file information to a remote attacker. This file contains sensitive information such as the administrative password for the device.
Disclosure Timeline:
Vendor Informed Date :2012-07-11
Vendor Ack Date :2012-07-12
Vendor Solution Date :2012-08-15
Disclosure Date :2013-01-31
Exploit Publish Date :2013-01-31