A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.
D-Link has released a security advisory and a software update for the affected camera model. Please visit this D-Link Security Announcement https://supportannouncement.us.dlink.com/security/publication.aspx for further information.D-Link strongly urges all users to install the relevant updates and
regularly check for further updates. After downloading the software
update, it is essential to ALWAYS validate its success by comparing the
software version on your product interface to the software update
version.
The model number listed in this advisory is known only for D-Link
India Limited. Users of cameras produced by the other listed vendors are
encouraged to evaluate this vulnerability within their environment.