CVE-2026-2218

A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/jinhao118/cve/blob/main/D-Link%20DCS933L_v1.14.11.md Exploit Third Party Advisory
https://github.com/jinhao118/cve/blob/main/D-Link%20DCS933L_v1.14.11.md#poc Exploit Third Party Advisory
https://vuldb.com/?ctiid.344936 Permissions Required VDB Entry
https://vuldb.com/?id.344936 Third Party Advisory VDB Entry
https://vuldb.com/?submit.753247 Third Party Advisory VDB Entry
https://www.dlink.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dcs-933l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-933l:-:*:*:*:*:*:*:*

History

11 Feb 2026, 18:33

Type Values Removed Values Added
CPE cpe:2.3:h:dlink:dcs-933l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-933l_firmware:*:*:*:*:*:*:*:*
First Time Dlink
Dlink dcs-933l
Dlink dcs-933l Firmware
References () https://github.com/jinhao118/cve/blob/main/D-Link%20DCS933L_v1.14.11.md - () https://github.com/jinhao118/cve/blob/main/D-Link%20DCS933L_v1.14.11.md - Exploit, Third Party Advisory
References () https://github.com/jinhao118/cve/blob/main/D-Link%20DCS933L_v1.14.11.md#poc - () https://github.com/jinhao118/cve/blob/main/D-Link%20DCS933L_v1.14.11.md#poc - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.344936 - () https://vuldb.com/?ctiid.344936 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.344936 - () https://vuldb.com/?id.344936 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.753247 - () https://vuldb.com/?submit.753247 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product

09 Feb 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 06:16

Updated : 2026-02-11 18:33


NVD link : CVE-2026-2218

Mitre link : CVE-2026-2218

CVE.ORG link : CVE-2026-2218


JSON object : View

Products Affected

dlink

  • dcs-933l_firmware
  • dcs-933l
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')