CVE-2026-36983: Command Injection
Published May 11, 2026
·Updated
D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.
Affected Software
3 affected components
D-Link DCS-932L=2.18.01
All of the following
Dlink Dcs-932l Firmware=2.18.01
Dlink Dcs-932l
Event History
May 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-36983?
CVE-2026-36983 is classified as a high severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2026-36983?
To mitigate CVE-2026-36983, upgrade your D-Link DCS-932L device to the latest firmware version available.
3
What types of attacks can exploit CVE-2026-36983?
CVE-2026-36983 can be exploited by attackers to execute arbitrary commands on the affected device.
4
Which versions of the D-Link DCS-932L are affected by CVE-2026-36983?
CVE-2026-36983 specifically affects D-Link DCS-932L devices running firmware version 2.18.01.
5
What component of the D-Link DCS-932L is vulnerable in CVE-2026-36983?
CVE-2026-36983 affects the function sub_42EF14 in the /bin/alphapd component of the D-Link DCS-932L.