CVE-2025-13607 PUBLISHED

D-Link CCTV camera model DCS-F5614-L1 Missing Authentication for Critical Function

Assigner: icscert
Reserved: 24.11.2025 Published: 10.12.2025 Updated: 11.12.2025

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor D-Link
Product DCS-F5614-L1
Versions Default: unknown
  • affected from 0 to 1.03.038 (incl.)

Solutions

D-Link has released a security advisory and a software update for the affected camera model. Please visit this D-Link Security Announcement https://supportannouncement.us.dlink.com/security/publication.aspx  for further information.D-Link strongly urges all users to install the relevant updates and regularly check for further updates. After downloading the software update, it is essential to ALWAYS validate its success by comparing the software version on your product interface to the software update version.

The model number listed in this advisory is known only for D-Link India Limited. Users of cameras produced by the other listed vendors are encouraged to evaluate this vulnerability within their environment.

Credits

  • Souvik Kandar finder

References

Problem Types

  • CWE-306 CWE